Skip to main content

Windows Admin Center / Management Tools

Log NameEvent IDSeverityDescription
Microsoft-Windows-ServerManager-ManagementProvider/Operational1000InformationServer Manager management provider started
Microsoft-Windows-ServerManager-ManagementProvider/Operational1001InformationServer Manager management provider stopped
Microsoft-Windows-ServerManager-ManagementProvider/Operational1100ErrorServer Manager failed to connect to target server
Microsoft-Windows-ServerManager-ManagementProvider/Operational1101InformationServer Manager successfully connected to target server
Microsoft-Windows-ServerManager-ManagementProvider/Operational1200InformationServer Manager initiated refresh of roles and features
Microsoft-Windows-ServerManager-ManagementProvider/Operational1300ErrorUnexpected error while managing target server
Microsoft-Windows-WindowsAdminCenter/Operational3000InformationWindows Admin Center gateway service started
Microsoft-Windows-WindowsAdminCenter/Operational3001WarningWindows Admin Center gateway service stopped
Microsoft-Windows-WindowsAdminCenter/Operational3002InformationAdmin Center user authenticated successfully
Microsoft-Windows-WindowsAdminCenter/Operational3003WarningAdmin Center user authentication failed
Microsoft-Windows-WindowsAdminCenter/Operational3004InformationUser accessed a managed node via Admin Center
Microsoft-Windows-WindowsAdminCenter/Operational3005WarningUnauthorized attempt to access managed node
Microsoft-Windows-WindowsAdminCenter/Operational3010InformationConfiguration file modified
Microsoft-Windows-WindowsAdminCenter/Operational3011InformationCertificate updated or renewed
Microsoft-Windows-WindowsAdminCenter/Operational3015InformationAdmin Center extension installed or removed
Microsoft-Windows-WindowsAdminCenter/Operational3020WarningConnection lost to managed node
Microsoft-Windows-WindowsRemoteManagement/Operational6InformationWinRM service started
Microsoft-Windows-WindowsRemoteManagement/Operational7InformationWinRM service stopped
Microsoft-Windows-WindowsRemoteManagement/Operational16InformationWinRM client connected to remote system
Microsoft-Windows-WindowsRemoteManagement/Operational17ErrorWinRM connection failed (access denied or timeout)
Microsoft-Windows-WindowsRemoteManagement/Operational18InformationWinRM listener started
Microsoft-Windows-WindowsRemoteManagement/Operational19InformationWinRM listener stopped
Microsoft-Windows-WindowsRemoteManagement/Operational20WarningWinRM configuration modified
Microsoft-Windows-PowerShell/Operational4100InformationPowerShell remote session started
Microsoft-Windows-PowerShell/Operational4101InformationPowerShell command executed
Microsoft-Windows-PowerShell/Operational4102ErrorPowerShell script execution failed
Microsoft-Windows-PowerShell/Operational4104InformationScript block logging — executed command captured
Microsoft-Windows-PowerShell/Operational4105WarningPowerShell session disconnected
Microsoft-Windows-PowerShell/Operational4106InformationPowerShell session reconnected
Microsoft-Windows-PowerShell/Operational53504WarningUnauthorized PowerShell activity blocked
Security4688InformationNew process created (admin tool execution trace)
Security4670WarningPermissions on management files or WAC config modified
System7036InformationWinRM service entered running/stopped state
Microsoft-Windows-ServerManager/Operational1001MediumManagement console failed to load data
Microsoft-Windows-ServerManager/Operational1003MediumRefresh operation failed
Microsoft-Windows-ServerManager/Operational1010HighServer Manager task failed
Microsoft-Windows-PowerShell/Operational4103HighPowerShell command failure
Microsoft-Windows-PowerShell/Operational4104HighSuspicious script execution
Microsoft-Windows-Eventlog1102CriticalAudit log cleared