Skip to main content

Host Guardian Service (HGS)

Log NameEvent IDSeverityDescription
Microsoft-Windows-HostGuardianService-Admin1000InfoHost Guardian Service started successfully
Microsoft-Windows-HostGuardianService-Admin1001InfoHost Guardian Service stopped
Microsoft-Windows-HostGuardianService-Admin1010MediumHGS configuration changed
Microsoft-Windows-HostGuardianService-Admin1015HighHGS initialization failed
Microsoft-Windows-HostGuardianService-Admin1017InfoHGS service listening endpoint created
Microsoft-Windows-HostGuardianService-Attestation2000InfoAttestation request received from host
Microsoft-Windows-HostGuardianService-Attestation2001InfoAttestation succeeded
Microsoft-Windows-HostGuardianService-Attestation2002HighAttestation failed (TPM or policy mismatch)
Microsoft-Windows-HostGuardianService-Attestation2003HighHost not registered or untrusted
Microsoft-Windows-HostGuardianService-Attestation2005CriticalAttestation service unavailable
Microsoft-Windows-HostGuardianService-KeyProtection3000InfoKey release request from host
Microsoft-Windows-HostGuardianService-KeyProtection3001InfoKey released to trusted host
Microsoft-Windows-HostGuardianService-KeyProtection3002HighKey release denied (untrusted host)
Microsoft-Windows-HostGuardianService-KeyProtection3004HighKey release service failed
Microsoft-Windows-HostGuardianService-KeyProtection3006MediumShielded VM unseal failure reported
Microsoft-Windows-HostGuardianService-Admin4000InfoHGS certificate renewal succeeded
Microsoft-Windows-HostGuardianService-Admin4001HighHGS certificate renewal failed
Microsoft-Windows-HostGuardianService-Admin4002HighAD trust validation with domain controller failed
Microsoft-Windows-HostGuardianService-Admin4003HighRoot or intermediate certificate missing
Microsoft-Windows-HostGuardianService-Admin4004MediumTPM or attestation policy modified
Security4624InfoSuccessful HGS service account logon
Security4625HighFailed HGS authentication attempt
Security4670MediumPermissions on HGS registry or files changed
Microsoft-Windows-HostGuardianService-Admin5001HighUnauthorized configuration attempt detected
Microsoft-Windows-HostGuardianService-Admin5003CriticalPolicy integrity violation detected