Skip to main content

Windows identity and security event channels

33channels
0curated reasons
0themes fed
Plannedstatus

Identity, secrets, code integrity and policy channels, bound as one feed: LAPS, BitLocker, Code Integrity, AppLocker, Group Policy, certificate and key stores, biometrics and passkeys, device registration and Entra join, logon and profile. Light curation: severity capped at Warning, nothing dropped, no reasons yet.

Feed id: win.eventlog.identity_security.

Channels

This feed binds 33 Windows Event Log channels as one reporting axis. A channel that a given Windows edition, role or OEM does not provide is absent on that endpoint; the rest still collect.

The ticket class is the subject area an event on the channel is evidence for, and it is what fleet-wide questions group by. A channel that records across every subject area at once ships unlabeled rather than mislabeled.

ChannelTicket class
Microsoft-Windows-AAD/Operationalauth
Microsoft-Windows-AppLocker/EXE and DLLsecurity_audit
Microsoft-Windows-AppLocker/MSI and Scriptsecurity_audit
Microsoft-Windows-AppLocker/Packaged app-Deploymentsecurity_audit
Microsoft-Windows-AppLocker/Packaged app-Executionsecurity_audit
Microsoft-Windows-Authentication User Interface/Operationalauth
Microsoft-Windows-Biometrics/Operationalauth
Microsoft-Windows-BitLocker/BitLocker Management
Microsoft-Windows-CAPI2/Operationalcertificates
Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operationalcertificates
Microsoft-Windows-CertificateServicesClient-Lifecycle-User/Operationalcertificates
Microsoft-Windows-CodeIntegrity/Operationalsecurity_audit
Microsoft-Windows-Crypto-DPAPI/Operationalcertificates
Microsoft-Windows-Crypto-NCrypt/KeyMgmtcertificates
Microsoft-Windows-Crypto-NCrypt/Operationalcertificates
Microsoft-Windows-EnrollmentPolicyWebService/Admincertificates
Microsoft-Windows-EnrollmentWebService/Admincertificates
Microsoft-Windows-GroupPolicy/Operationaldevice_management
Microsoft-Windows-HelloForBusiness/Operationalauth
Microsoft-Windows-LAPS/Operationalauth
Microsoft-Windows-LiveId/Operationalauth
Microsoft-Windows-NTLM/Operationalauth
Microsoft-Windows-Security-Mitigations/KernelModesecurity_audit
Microsoft-Windows-Security-Mitigations/UserModesecurity_audit
Microsoft-Windows-SENSE/Operationalendpoint_protection
Microsoft-Windows-SmartCard-Audit/Authenticationauth
Microsoft-Windows-SmartCard-DeviceEnum/Operationalauth
Microsoft-Windows-UAC/Operationalsecurity_audit
Microsoft-Windows-User Device Registration/Admindevice_management
Microsoft-Windows-User Profile Service/Operationaluser_profiles
Microsoft-Windows-WebAuthN/Operationalauth
Microsoft-Windows-Winlogon/Operationalauth
Microsoft-Windows-Workplace Join/Admindevice_management

Severity

This feed is bound for collection but is not yet curated per event. Every event keeps the severity its own provider stated, capped at Warning.

Ask this feed a question

Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.