Windows identity and security event channels
Identity, secrets, code integrity and policy channels, bound as one feed: LAPS, BitLocker, Code Integrity, AppLocker, Group Policy, certificate and key stores, biometrics and passkeys, device registration and Entra join, logon and profile. Light curation: severity capped at Warning, nothing dropped, no reasons yet.
Feed id: win.eventlog.identity_security.
Channels
This feed binds 33 Windows Event Log channels as one reporting axis. A channel that a given Windows edition, role or OEM does not provide is absent on that endpoint; the rest still collect.
The ticket class is the subject area an event on the channel is evidence for, and it is what fleet-wide questions group by. A channel that records across every subject area at once ships unlabeled rather than mislabeled.
| Channel | Ticket class |
|---|---|
Microsoft-Windows-AAD/Operational | auth |
Microsoft-Windows-AppLocker/EXE and DLL | security_audit |
Microsoft-Windows-AppLocker/MSI and Script | security_audit |
Microsoft-Windows-AppLocker/Packaged app-Deployment | security_audit |
Microsoft-Windows-AppLocker/Packaged app-Execution | security_audit |
Microsoft-Windows-Authentication User Interface/Operational | auth |
Microsoft-Windows-Biometrics/Operational | auth |
Microsoft-Windows-BitLocker/BitLocker Management | |
Microsoft-Windows-CAPI2/Operational | certificates |
Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational | certificates |
Microsoft-Windows-CertificateServicesClient-Lifecycle-User/Operational | certificates |
Microsoft-Windows-CodeIntegrity/Operational | security_audit |
Microsoft-Windows-Crypto-DPAPI/Operational | certificates |
Microsoft-Windows-Crypto-NCrypt/KeyMgmt | certificates |
Microsoft-Windows-Crypto-NCrypt/Operational | certificates |
Microsoft-Windows-EnrollmentPolicyWebService/Admin | certificates |
Microsoft-Windows-EnrollmentWebService/Admin | certificates |
Microsoft-Windows-GroupPolicy/Operational | device_management |
Microsoft-Windows-HelloForBusiness/Operational | auth |
Microsoft-Windows-LAPS/Operational | auth |
Microsoft-Windows-LiveId/Operational | auth |
Microsoft-Windows-NTLM/Operational | auth |
Microsoft-Windows-Security-Mitigations/KernelMode | security_audit |
Microsoft-Windows-Security-Mitigations/UserMode | security_audit |
Microsoft-Windows-SENSE/Operational | endpoint_protection |
Microsoft-Windows-SmartCard-Audit/Authentication | auth |
Microsoft-Windows-SmartCard-DeviceEnum/Operational | auth |
Microsoft-Windows-UAC/Operational | security_audit |
Microsoft-Windows-User Device Registration/Admin | device_management |
Microsoft-Windows-User Profile Service/Operational | user_profiles |
Microsoft-Windows-WebAuthN/Operational | auth |
Microsoft-Windows-Winlogon/Operational | auth |
Microsoft-Windows-Workplace Join/Admin | device_management |
Severity
This feed is bound for collection but is not yet curated per event. Every event keeps the severity its own provider stated, capped at Warning.
Ask this feed a question
Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.