This event is signalled when device changes status of registration in Azure Active Directory.
This event is bool signaled to indicate the EC accessibility feature enabled state
Indicates Activity Data has been updated
A system entity has requested a change in AFD's orderly release behavior.
This state is incremented when a discrete part of the AoW boot sequence has completed. Security: WNF_STATE_SUBSCRIBE (1) by everyone (WD) and app containers (S-1-15-2-1); WNF_STATE_SUBSCRIBE | WNF_STATE_PUBLISH (3) by Local System (SY) and the Interactive User account (IU).
Contains the current stream state information for the app broadcast service.
AppInstallation state name to receive RAW notifications
This event is signalled when a package install operation completes
This event is signalled when a package update operation completes
This event is signalled when a package uninstall operation completes
An app implementing windows.AppUriHandler contract has been installed
This event is fired when all critical packages (those that need to be installed before the shell is displayed) have installed.
Mobile lockdown configuration has been changed
Curate tile collection for all allowed apps for current AssignedAccess account has been created
Events are logged to the assigned access status trace logging.
This state holds the CPU Set ID for audio threads. CAPABILITY_SID_LpacMedia - S-1-15-3-1024-1692970155-4054893335-185714091-3362601943-3526593181-1159816984-2199008581-497492991.
This state indicates an active phone call, which can be from a cellular call or active Communications category audio streams
This notification indicates whether or not the tuner endpoint is available.
State for problems detected in the audio core.
This state keeps other system services apprised of the audio-reserved CPU set ID.
Reports the number of, and all endpoints currently rendering audio. Returns a WNF_STREAM_EVENT_HEADER data structure
This notification is raised when contextual volume for endpoints have changed.
Reports the number of, and process ids of all applications currently capturing audio. Returns a WNF_CAPTURE_STREAM_EVENT_HEADER data structure
Reports the changes to the Ringervibrate state of the device
Reports for each spatial audio endpoint if spatial audio is currently being rendered. Returns a WNF_SPATIAL_STATUS_HEADER data structure
Reports certain properties of the default render multimedia endpoint whenever the default endpoint changes or a property of interest changes on the default render endpoint
Publishes a list of the current chat applications on the device
Reports whether or not the voice activation manager has an active hardware keyword spotter.
This notification is used to signal that a match has been detected for Voice Activation
A driver requst permission for volume limit change.
This event propagates the user's choice from the warning dialog.
This event informs the system that we need to show reached volume limit warning message
Event fired when we scan the System Partition and find corruption.
The background media player's playstate has changed.
The following tasks aren't able to play under current policy
IP Over USB Availability. SDDL comes from ID_CAP_EVERYONE and IpOverUsb in %SDXROOT%\src\baseos\prod\packages\MfgIpOverUsb\MfgIpOverUsb.pkg.xml
Update progress reporting status. SDDL comes from ID_CAP_BASEOS_UPDATEAPI in %SDXROOT%\src\baseos\prod\packages\imgupd\MainOS\ImgUpd.pkg.xml
This event triggers when Device Encryption support status is evaluated, and receives the result of that evaluation.
This event triggers when the BitLocker service detects a change in the count of DE-managed volumes, and includes the count of such volumes.
This event triggers or signals to stop WIM hash generation task.
This event signals completion of WIM hash generation.
This event triggers WIM hash deletion.
This event trigger-starts BdeSvc service.
This event triggers on every BitLocker state change.
This event triggers where RequireDeviceEncryption policy arrives under the BitLocker area.
This event triggers SD card encrytion policy arrival notification.
This event triggers SecTask to enable/disable SD Card encryption.
This event indicates completion of SD Card encryption/decryption request.
This event trigger-starts device encryption task.
This event triggers BitLocker task to enable BitLocker on all volumes.
State of the synchronous provisioning phase of WCOS DE.
State name for Bluetooth overall status notification. Flags from the BLUETOOTH_GLOBAL_STATUS enum are returned. SDDL comes from ID_CAP_EVERYONE and BTConnMgr in %SDXROOT%\src\net\Bluetooth\Packages\Product\Bluetooth\Bluetooth.pkg.xml
State name for Bluetooth Audio Gateway status notification. A 32-bit bitmask of BLUETOOTH_AUDIO_GATEWAY_STATUS enum are returned. SDDL comes from ID_CAP_EVERYONE and BTAGService in %SDXROOT%\src\net\Bluetooth\Packages\Product\Bluetooth\Bluetooth.pkg.xml
State name for Bluetooth MAP status notification. A 32-bit bitmask of BLUETOOTH_MAP_STATUS enum are returned.
Indicates when a Bluetooth Device gets connected and disconnected
Indicates that a legacy Gatt client request is present. The local radio and remote device BTH_ADDR are returned.
Indicates that a legacy Gatt client request was no longer present. The previously granted access token to be revoked is returned.
Notification that the user requested a change to the status of the QuickPair engine.
Notification that the user has changed the volume level using AVRCP on a Bluetooth peripheral.
Notification that a Bluetooth device's battery is low.
Exposes the status of Bluetooth LE Advertisement scanning.
Signals for the PBAP Consent UI to be shown
Aggregated status for one or more Bluetooth peripheral charging docks located on the system.
Notification that a HFP Hands-Free line is available. BTAGService can publish. Authenticated users and PhoneSvc can subscribe.
The state is published once the previous shutdown was not clean.
The state is published if system time is initialized with a backup time source.
The state reflects memory partiton restoration state (nothing to restore, restore in progress, restore completed, failure)
Notifies brightness classes of the active window in order to apply their brightness preferences
Background work execution trigger
BI user logon system state notification channel
BI user logoff system state notification channel
BI session connect system state notification channel
BI session disconnect system state notification channel
BI application uninstall system state notification channel
BI application servicing start system state notification channel
BI application servicing stop system state notification channel
BI lock screen update system state notification channel
BI event deletion system state notification channel
PSM policy test hook
BI Quiet Mode update system state notification channel
Indicates that BI is ready and also publish channels list for each session
BI notify new session system state notification channel
PSM notification to clients for querying application performance usage
Notification that the system is entering or exiting a network limited standby
A button press has caused a request.
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when access to the corresponding named app capability changes
Event fired when usage of the corresponding named app capability changes
Event fired when usage of the corresponding named app capability changes
Event fired when usage of the corresponding named app capability changes
Event fired when usage of the corresponding named app capability changes
Event fired when usage of the corresponding named app capability changes
Event fired when usage of the corresponding named app capability changes
Event fired when usage of the corresponding named app capability changes
Event fired when usage of the corresponding named app capability changes
Event fired when usage of the corresponding named app capability changes
Event fired when usage of the corresponding named app capability changes
Event fired when usage of the corresponding named app capability changes
Event fired when usage of the corresponding named app capability changes
Event fired when usage of the corresponding named app capability changes
Event fired when usage of the corresponding named app capability changes
Event fired when usage of the corresponding named app capability changes
Event fired when usage of the corresponding named app capability changes
Event fired when usage of the corresponding named app capability changes
Event fired when usage of the corresponding named app capability changes
Event fired when usage of the corresponding named app capability changes
Event fired when usage of the corresponding named app capability changes
Event fired when usage of the corresponding named app capability changes
Indicates CDP Service is ready
Indicates CDP Service is stopping
Indicates CDP User Service is ready
Indicates CDP User Service is stopping
Indicates CDP service queued the message(s) for designated applications
Indicates CDP service received new activities
Indicates that the user has changed the CDP policy
Indicates failure either delivering or invoking a Notification Action on a remote device
Indicates that the user has changed Rome SDK authorization setting
Indicates that the user has changed Near Share authorization setting
Indicates whether ActivityFeed is enabled. It is responsible for mirroring different activity types (as applicable) across device graph of the user.
Indicates the settings policy (enabled/disabled) for 'User Activity' publishing has changed.
Indicates CDP service received local activities
Indicates the persisted values associated with a resource has changed.
Indicates the settings policy (enabled/disabled) for 'User Activity' upload has changed.
Indicates clipboard history policy has changed.
Indicates cross device clipboard policy has changed.
Modem power state of the first modem, values defined by MODEMPOWERSTATE. SDDL comes from ID_CAP_CELL_API_COMMON, ID_CAP_EVERYONE, ImsSvc and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Number of bars (0..5) of signal strength for the first cellular can. In the case of dual registration (SVLTE or CDMA) this is the primary signal strength. SDDL comes from ID_CAP_EVERYONE and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
System type of the first cellular Can, a bitmask of RIL_SYSTEMTYPE_ values. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Current registration status of the first cellular can, bits defined by RILREGSTAT. SDDL comes from ID_CAP_EVERYONE and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Status of the UICC in the first slot. SDDL comes from ID_CAP_EVERYONE and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
The current state of airplanemode. SDDL comes from ID_CAP_CELL_WNF, WwanSvc and Airplanemode (service) in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Current serving operator for the first cellular can, name as a Unicode string. SDDL comes from ID_CAP_EVERYONE and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Activation, PRL, and provisioning state for the first cellular can. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
NITZ information for the first cellular can. SDDL comes from ID_CAP_CELL_API_COMMON, ID_CAP_CELL_WNF, WwanSvc and tzautoupdate in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
List of available operators for the first cellular can, an array of RILOPERATORINFO. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Device info (RIL_GetDeviceInfo) for the first cellular can, as a set of Unicode strings. SDDL comes from ID_CAP_CELL_WNF_PII and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Cellular data enabled state as set by user. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Phone number (MSISDN) for the first cellular can, as a Unicode string. SDDL comes from ID_CAP_CELL_WNF_PII and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Voicemail number (MBDN) for the first cellular can, as a Unicode string. SDDL comes from ID_CAP_CELL_WNF_PII and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Registration preferences for the first cellular can. SDDL comes from ID_CAP_CELL_API_COMMON, ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Can state (between CellManager and CellUX) for the first cellular can. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Power state of the modem as last preferred by the user, values defined by MODEMPOWERSTATE. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
The current state of airplanemode details. SDDL comes from ID_CAP_CELL_WNF, WwanSvc and Airplanemode (service) in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
This is triggered if cellcore suspects that data activity may have been affected. SDDL comes from ID_CAP_EVERYONE and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Root state describing cellular system configuration (all modems and their cans). SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Detailed registration status of the first cellular can, defined by WNFCELLSTATETYPE(REGISTRATION_STATUS_DETAILS). SDDL comes from ID_CAP_CAMERA, ID_CAP_CELL_WNF, ID_CAP_EVERYONE, ID_CAP_ISV_CAMERA, WwanSvc, ImsSvc and tzautoupdate in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
bitmask of supported system types by the first cellular can. SDDL comes from ID_CAP_CELL_API_COMMON, ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
bitmask of supported system types by the first cellular can. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
MCC, MNC (or SID, NID) of the 'home' operator. SDDL comes from ID_CAP_CAMERA, ID_CAP_CELL_WNF, ID_CAP_ISV_CAMERA and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
PRL ID of 'home' operator. Is Valid only if there is a valid 3GPP2 line available. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
UICC toolkit setup menu notification for slot 0. SDDL comes from ID_CAP_CELL_WNF_PII and UtkService in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
UICC toolkit proactive command notification for all slots. SDDL comes from ID_CAP_CELL_WNF_PII and UtkService in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
CM CSPWWAN+ readyness state. SDDL comes from ID_CAP_CMCSPWWAN_PLUS in %SDXROOT%\src\net\NetCore\Packages\NetCore\NetCore.pkg.xml
Call-forwarding status for the first cellular can. The same struct is used to indicate the latest state for a given callforwarding-reason. SDDL comes from ID_CAP_CELL_API_TELEPHONY, ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Modem radio type of the first modem, values defined by RILRADIOCONFIGURATIONRADIOTYPE. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Number of bars (0..5) of signal strength for the second cellular can. In the case of dual registration (SVLTE or CDMA) this is the primary signal strength. SDDL comes from ID_CAP_EVERYONE and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
System type of the second cellular Can, a bitmask of RIL_SYSTEMTYPE_ values. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Current registration status of the second cellular can, bits defined by RILREGSTAT. SDDL comes from ID_CAP_EVERYONE and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Status of the UICC in the second slot. SDDL comes from ID_CAP_EVERYONE and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Current serving operator for the second cellular can, name as a Unicode string. SDDL comes from ID_CAP_EVERYONE and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Activation, PRL, and provisioning state for the second cellular can. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
NITZ information for the second cellular can. SDDL comes from ID_CAP_CELL_API_COMMON, ID_CAP_CELL_WNF, WwanSvc and tzautoupdate in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
List of available operators for the second cellular can, an array of RILOPERATORINFO. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Device info (RIL_GetDeviceInfo) for the second cellular can, as a set of Unicode strings. SDDL comes from ID_CAP_CELL_WNF_PII and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Phone number (MSISDN) for the second cellular can, as a Unicode string. SDDL comes from ID_CAP_CELL_WNF_PII and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Registration preferences for the second cellular can. SDDL comes from ID_CAP_CELL_API_COMMON, ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Can state (between CellManager and CellUX) for the second cellular can. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Detailed registration status of the second cellular can, defined by WNFCELLSTATETYPE(REGISTRATION_STATUS_DETAILS). SDDL comes from ID_CAP_CELL_WNF, ID_CAP_EVERYONE, WwanSvc, ImsSvc and tzautoupdate in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
bitmask of supported system types by the second cellular can. SDDL comes from ID_CAP_CELL_API_COMMON, ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
MCC, MNC (or SID, NID) of the 'home' operator. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
PRL ID of 'home' operator. Is Valid only if there is a valid 3GPP2 line available. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
UICC toolkit setup menu notification for slot 1. SDDL comes from ID_CAP_CELL_WNF_PII and UtkService in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Call-forwarding status for the second cellular can. The same struct is used to indicate the latest state for a given callforwarding-reason. SDDL comes from ID_CAP_CELL_API_TELEPHONY, ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
bitmask of supported system types by the second cellular can. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Configured lines for the first cellular can. SDDL comes from ID_CAP_CELL_API_COMMON, ID_CAP_CELL_WNF, ImsSvc and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Configured lines for the second cellular can. SDDL comes from ID_CAP_CELL_API_COMMON, ID_CAP_CELL_WNF, ImsSvc and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Status details of the UICC in the first slot. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Status details of the UICC in the second slot. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Preferred languages in the first slot. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Preferred languages in the second slot. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
IMSI for the first cellular can, as a Unicode string. SDDL comes from ID_CAP_CELL_WNF_PII and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
IMSI for the first cellular can, as a Unicode string. SDDL comes from ID_CAP_CELL_WNF_PII and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Migration action for legacy cellcore settings. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Answer to reset from the UICC in the first slot. SDDL comes from ID_CAP_CELL_WNF in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Answer to reset from the UICC in the second slot. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Indication for Phone subsystem to show Sim Security (PIN, Perso) related UI for Slot 0. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Indication for Phone subsystem to show Sim Security (PIN, Perso) related UI for Slot 1. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Indication that all executors have been configured and that there are no outstanding configurations pending in the modem. SDDL comes from WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
This is published when cellcore needs MV to kick in. SDDL comes from ID_CAP_EVERYONE, ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Signal-strength details for Can 0. SDDL comes from ID_CAP_EVERYONE and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Signal-strength details for Can 1. SDDL comes from ID_CAP_EVERYONE and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Indication about the current emergency callback mode. SDDL comes from ID_CAP_EVERYONE and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Current IMS registration for Can 0. SDDL comes from ID_CAP_EVERYONE and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Current IMS registration for Can 1. SDDL comes from ID_CAP_EVERYONE and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
iWLAN availability for Can 0, value is BOOLEAN. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
iWLAN availability for Can 1, value is BOOLEAN. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
PS Media preferences for Can 0, a DWORD and an array of CellularMediaConfigration. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
PS Media preferences for Can 1, a DWORD and an array of CellularMediaConfigration. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Reports if executor is capable of Wi-fi calling. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Reports if executor is capable of Wi-fi calling. SDDL comes from ID_CAP_CELL_WNF and WwanSvc in %SDXROOT%\src\net\Cellcore\packages\Cellcore\Cellcore.pkg.xml
Reports detailed states of PIN on slot 0. It is private for Wwansvc access only
Reports detailed states of PIN on slot 1. It is private for Wwansvc access only
NITZ information received from the modem. SDDL comes from ID_CAP_CELL_WNF, WwanSvc and tzautoupdate
Table of all modems and executors under it.
This event is published by WwanSvc to indicate the arrival of an eUICC.
This event is published by WwanSvc to indicate a change in cellular state snapshot.
State name triggering WiFiTask from WwanSvc.
Sms Router Broker is ready.
Sms Router Broker is ready.
Sms Router received a new incoming SMS message.
Push Notification Received from Entitlement Server
This event signals flush cache in all processes where flush is enabled.
This event signals when flush cache was started and completed in each process where enabled.
Central Access Policies have been updated
This notification is triggered when contents on the clipboard change
This notification is triggered when contents of the clipboard history change
This notification is triggered when roaming clipboard enabled/disabled setting value changes
This notification is triggered when clipboard history enabled/disabled setting value changes
Indicates Clipboard User Service is ready
Indicates Clipboard User Service has stopped
Notification of web app status change. Payload is status type plus web app cxid of length 512
Notification when CloudExperienceHost app is finished. Payload is result plus result string of length 512
Notification of web app back button state. Payload is a boolean for on/off
Notification when back command is issued
System-wide signal that the CloudExperienceHost app launched during OOBE is ready with its first webapp visible. Payload is a boolean for true/false
This event signals that change of S mode has occurred.
Core shell has initialized, including all of its services (e.g. TLAVM), and the Product Composer can be launched. If the event has not been fired, then CoreShell is still initializing and the Composer cannot be launched. Payload is a DWORD to inidicate it has been fired.
On UI Automation.
Fired every time a Composer registers with TLAVM and inidicates that the composer is ready to host applications. If the event has not been fired, then no composer is ready to host applications. Payload is a DWORD to inidicate it has been fired.
Fired every time a Product Composer has finished initializing and indicates that Shell has entered normal operations (i.e. not in restricted mode or running OOBE/PostUpdateUX). If the event has not been fired, then the Product Composer is still initializing. Payload is a DWORD to inidicate it has been fired.
When set to the value 1, it indicates that the current composer has finished unintializing.
Indicates the composer has changed which updates the registry (ComposerManagerBaseKey) indicating which composer can be restored after a crash
Fired when a test job wants to skip CXH stage of OOBE
Triggered each time one or more flight configurations changes.
Triggered each time one or more flight configurations is deleted.
Triggered each time one or more flight configurations is added.
Components blocked waiting for restore from snapshot can now continue
A request has been raised for CustomShellHost to launch Explorer.exe as shell
This event triggers when the Delivery Optimization service manager is active or idle
Delivery Optimization system policy has been updated
This event triggers when the user changes device access for an applocation or the user
This event signals when authentication stage change.
Notification for when an app is installed so we can register a device background task if necessary.
Notification for when an app is removed so we can clean up any registered device background tasks if necessary.
Signals that Migration started. DWORD[1] = {started flag}. SDDL comes from ID_CAP_DU_MIGRATION_WNF_EVENTS and DuMigrationManager in %SDXROOT%\src\devmgmt\du\packages\Migration\Migration.pkg.xml and WINCAP_SHELL_EXPERIENCE_COMPOSER in %SDXROOT%\shellcommon\Composable\Core\dll\microsoft-windows-coreshell.wm.xml
Signals that Migration completed. DWORD[2] = {completed flag, status}. SDDL comes from ID_CAP_DU_MIGRATION_WNF_EVENTS and DuMigrationManager in %SDXROOT%\src\devmgmt\du\packages\Migration\Migration.pkg.xml and WINCAP_SHELL_EXPERIENCE_COMPOSER in %SDXROOT%\shellcommon\Composable\Core\dll\microsoft-windows-coreshell.wm.xml
Current Migration state. DWORD[4] = {Phase, Total Phases, Step, Total Steps}. SDDL comes from ID_CAP_DU_MIGRATION_WNF_EVENTS and DuMigrationManager in %SDXROOT%\src\devmgmt\du\packages\Migration\Migration.pkg.xml and WINCAP_SHELL_EXPERIENCE_COMPOSER in %SDXROOT%\shellcommon\Composable\Core\dll\microsoft-windows-coreshell.wm.xml
Signals when data migration is complete after reboot and update results need to be displayed. DWORD[1] = {completed flag}. SDDL comes from ID_CAP_DU_MIGRATION_WNF_EVENTS in %SDXROOT%\src\devmgmt\du\packages\Migration\Migration.pkg.xml and DuPostUpdateUX in %SDXROOT%\src\devmgmt\du\packages\UX\UX.pkg.xml and WINCAP_SHELL_EXPERIENCE_COMPOSER in %SDXROOT%\shellcommon\Composable\Core\dll\microsoft-windows-coreshell.wm.xml
Some value under Policies registry key has been updated
State stores the current stereo cpl setting. CAPABILITY_SID_LpacMedia - S-1-15-3-1024-1692970155-4054893335-185714091-3362601943-3526593181-1159816984-2199008581-497492991.
Triggered by kernel when mode change happens. CAPABILITY_SID_LpacMedia - S-1-15-3-1024-1692970155-4054893335-185714091-3362601943-3526593181-1159816984-2199008581-497492991.
Triggered by kernel when any occlusion related OS state change happens.
Triggered by kernel when the state of a network display device is changed.
Triggered by kernel when monitor change happens. CAPABILITY_SID_LpacMedia - S-1-15-3-1024-1692970155-4054893335-185714091-3362601943-3526593181-1159816984-2199008581-497492991.
Triggered by kernel when video memory has to be trimmed. CAPABILITY_SID_LpacMedia - S-1-15-3-1024-1692970155-4054893335-185714091-3362601943-3526593181-1159816984-2199008581-497492991.
Triggered by kernel when video memory budget for an application changes. CAPABILITY_SID_LpacMedia - S-1-15-3-1024-1692970155-4054893335-185714091-3362601943-3526593181-1159816984-2199008581-497492991.
Triggered by hardware content protection tilt detection. CAPABILITY_SID_LpacMedia - S-1-15-3-1024-1692970155-4054893335-185714091-3362601943-3526593181-1159816984-2199008581-497492991.
Stores information about the physical dimensions (in mm) of the integrated panel if available, and 0's if not.
Triggered when a lowbox application starts or stops using OutputDuplication.
Triggered by kernel when a change is made to the display configuration.
Triggered when a device has been removed for any reason, not just adapter removal. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
Triggered when a lowbox application starts or stops using OutputDuplication and provides list of active lowbox contexts
Triggered when the default color profile for any attached display changes. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622
State is used to indicate the process that should be targeted by GPM.
Triggered by kernel when a GPU is started. CAPABILITY_SID_LpacMedia - S-1-15-3-1024-1692970155-4054893335-185714091-3362601943-3526593181-1159816984-2199008581-497492991.
Triggered by kernel when a GPU is stopped. CAPABILITY_SID_LpacMedia - S-1-15-3-1024-1692970155-4054893335-185714091-3362601943-3526593181-1159816984-2199008581-497492991.
Triggered by kernel when SDR white level value is changed for any display. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622
Triggered when any of the color overrides are changed for any display.
Triggered by kernel when colorimetry data is changed for any display. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622
Triggered when Vail states are changed for this remote session on virtual machine.
This event signals when a disk that requires scrubbing is brought online
Triggered by the kernel when any adapter receives a TDR or PNP event. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
Triggered by the kernel when an active display path asynchronously transitions to either a failed or invalidated state
When all the DNS Servers Timeout, this event is notified
Triggered when the dwm starts/terminates
Triggered when exclusive mode apps are presenting at a low framerate to the holographic compositor
Triggered when the compositor toggles between not having and having (any) protected content
Triggered when 3D compositor is presenting at a low framerate
Triggered when the dwm composition capabilities changes
Triggered when exclusive mode apps are presenting in the holographic compositor
State name for holding application window handle of calling UX
Narrator has moved its focused region
Represents whether Narrator is currently running. A 32-bit unsigned integer with a zero value meaning Narrator is off.
UISettings have changed. The payload carries an identifier for the particular setting that has changed, such as TextScaleFactor.
Indicates whether ATManager has already attempted to start user configured ATs for the current session.
Narrator keyboard remap state. 0 is the default value, 1 means keyboard remap page need to be opened.
This event is fired when a top level frame navigation is complete, the payload contains the host name
This event is fired when an extension is installed. The payload is the extension id
This event is fired on edge open if any extension is installed
This event is fired on edge open if any extension, supported in InPrivate, is installed
The application was launched in the specified mode under the specified Enterprise context.
The keys associated with a data protection identity were removed.
Current state of the Data Protection under Lock private keys
Either a copy or override operation occurred, leading to clipboard metadata changes. CAPABILITY_SID_LpacEnterprisePolicyChangeNotifications - S-1-15-3-1024-126078593-3658686728-1984883306-821399696-3684079960-564038680-3414880098-3435825201.
An EDP blocking dialog has been canceled programmatically.
Application UI EDP context has been changed for the process.
The AAD token used by EDP has expired.
The EDP enterprise contexts have been updated.
EDP process UI enforcement global state. CAPABILITY_SID_LpacEnterprisePolicyChangeNotifications - S-1-15-3-1024-126078593-3658686728-1984883306-821399696-3684079960-564038680-3414880098-3435825201.
EDP thread UI enforcement. CAPABILITY_SID_LpacEnterprisePolicyChangeNotifications - S-1-15-3-1024-126078593-3658686728-1984883306-821399696-3684079960-564038680-3414880098-3435825201.
Data Protection under Lock private keys will be dropped from memory shortly.
EDP cred service cannot access credentials required
Purge application learning events cache
Cred service is updating user credentials.
This event is triggered when an MDM printer policy is changed.
This event trigger-starts EFS service.
EFS service needs to check GP at boot, which requires the SOFTWARE hive in HKLM. This signals its availability when EFS worker thread detects it.
Current changed policy values represented as bits for the Device Lock policy area. SDDL comes from NgcctnrSvc in %SDXROOT%\src\baseos\prod\packages\ngc\ngc.pkg.xml and ID_CAP_POLICY_MANAGER and ID_CAP_POLICY_MANAGER_READONLY in %SDXROOT%\src\devmgmt\enterprise\product\policymanager\packages\policymanager.pkg.xml, %sdxroot%\onecoreuap\admin\dm\wap\service\dmwappushservice.wm.xml
Current changed policy values represented as bits for the Wifi policy area. SDDL comes from ID_CAP_POLICY_MANAGER and ID_CAP_POLICY_MANAGER_READONLY in %SDXROOT%\src\devmgmt\enterprise\product\policymanager\packages\policymanager.pkg.xml. S-1-5-80-3935728946-315639613-922904133-3250794525-491832002 - IcsSvc (TetheringService)
Current changed policy values represented as bits for the System policy area. SDDL comes from ID_CAP_POLICY_MANAGER and ID_CAP_POLICY_MANAGER_READONLY in %SDXROOT%\src\devmgmt\enterprise\product\policymanager\packages\policymanager.pkg.xmlSDDL comes from ID_CAP_POLICY_MANAGER and ID_CAP_POLICY_MANAGER_READONLY in %SDXROOT%\src\devmgmt\enterprise\product\policymanager\packages\policymanager.pkg.xml
Current changed policy values represented as bits for the Connectivity policy area. SDDL comes from ID_CAP_POLICY_MANAGER and ID_CAP_POLICY_MANAGER_READONLY in %SDXROOT%\src\devmgmt\enterprise\product\policymanager\packages\policymanager.pkg.xml
Current changed policy values represented as bits for the Experience policy area. SDDL comes from ID_CAP_POLICY_MANAGER and ID_CAP_POLICY_MANAGER_READONLY in %SDXROOT%\src\devmgmt\enterprise\product\policymanager\packages\policymanager.pkg.xml
Current changed policy values represented as bits for the Accounts policy area. SDDL comes from ID_CAP_POLICY_MANAGER and ID_CAP_POLICY_MANAGER_READONLY in %SDXROOT%\src\devmgmt\enterprise\product\policymanager\packages\policymanager.pkg.xml
Current changed policy values represented as bits for the Security policy area. SDDL comes from ID_CAP_POLICY_MANAGER and ID_CAP_POLICY_MANAGER_READONLY in %SDXROOT%\src\devmgmt\enterprise\product\policymanager\packages\policymanager.pkg.xml
Current changed policy values represented as bits for the Browser policy area. SDDL comes from ID_CAP_POLICY_MANAGER and ID_CAP_POLICY_MANAGER_READONLY in %SDXROOT%\src\devmgmt\enterprise\product\policymanager\packages\policymanager.pkg.xml
Current changed policy values represented as bits for the Update policy area. SDDL comes from ID_CAP_POLICY_MANAGER and ID_CAP_POLICY_MANAGER_READONLY in %SDXROOT%\src\devmgmt\enterprise\product\policymanager\packages\policymanager.pkg.xml
Current changed policy values represented as bits for the Camera policy area. SDDL comes from ID_CAP_POLICY_MANAGER and ID_CAP_POLICY_MANAGER_READONLY in %SDXROOT%\src\devmgmt\enterprise\product\policymanager\packages\policymanager.pkg.xml
Current changed policy values represented as bits for the ApplicationManagement policy area. SDDL comes from ID_CAP_POLICY_MANAGER and ID_CAP_POLICY_MANAGER_READONLY in %SDXROOT%\src\devmgmt\enterprise\product\policymanager\packages\policymanager.pkg.xml
Current changed security policy RequireDeviceEncryption value changed. SDDL comes from ID_CAP_POLICY_MANAGER and ID_CAP_POLICY_MANAGER_READONLY in %SDXROOT%\src\devmgmt\enterprise\product\policymanager\packages\policymanager.pkg.xml
An MDM Push notification has been received. SDDL comes from ID_CAP_CSP_DMCLIENT in %SDXROOT%\src\devmgmt\dm\packages\dmapps\dmapps.pkg.xml
Current changed policy values represented as bits for the Search policy area. SDDL comes from ID_CAP_POLICY_MANAGER and ID_CAP_POLICY_MANAGER_READONLY in %SDXROOT%\src\devmgmt\enterprise\product\policymanager\packages\policymanager.pkg.xml
Current changed policy values represented as bits for the AboveLock policy area. SDDL comes from ID_CAP_POLICY_MANAGER and ID_CAP_POLICY_MANAGER_READONLY in %SDXROOT%\src\devmgmt\enterprise\product\policymanager\packages\policymanager.pkg.xml
A Dataprotection AllowApplications provider policy value has changed.
A Dataprotection EDPEnforcementLevel provider policy value has changed.
A WAP message has been received that dmwappushsvc needs to handle.
An enterprise context has changed it's state
An enterprise WNS based push was received
A TextInput AllowInputPanel provider policy value has changed.
Allow use of diacritics for indexing.
Always use automatic language detection when indexing content and properties.
Do not allow locations on removable drives to be added to libraries.
Stop indexing in the event of limited hard drive space.
Allow indexing of encrypted files.
Bluetooth policy configuration has changed. SDDL comes from ID_CAP_POLICY_MANAGER in %SDXROOT%\src\devmgmt\enterprise\product\policymanager\packages\policymanager.pkg.xml
A Dataprotection networking policy value has changed.
DataProtection Require Protection Under Lock Config policy change.
Windows Defender policy configuration has changed.
ApplicationManagement AllowAllTrustedApps provider policy value has changed.
ApplicationManagement AllowSharedUserAppData provider policy value has changed.
ApplicationManagement RestrictAppToSystemVolume provider policy value has changed.
ApplicationManagement RestrictAppDataToSystemVolume provider policy value has changed.
ApplicationManagement AllowDeveloperUnlock provider policy value has changed.
Update AllowUpdateService provider policy value has changed.
Update UpdateServiceUrl provider policy value has changed.
Update AllowNonMicrosoftSignedUpdate provider policy value has changed.
DisableWBA policy value has changed.
The domains for which email is disabled have changed.
The AllowCellularDataRoaming policy value has changed.
The AllowCellularData policy value has changed.
EDPEnforcementLevel cached policy have changed. CAPABILITY_SID_LpacEnterprisePolicyChangeNotifications - S-1-15-3-1024-126078593-3658686728-1984883306-821399696-3684079960-564038680-3414880098-3435825201.
EnterpriseProtectedDomainNames cached policy have changed. CAPABILITY_SID_LpacEnterprisePolicyChangeNotifications - S-1-15-3-1024-126078593-3658686728-1984883306-821399696-3684079960-564038680-3414880098-3435825201.
The AllowMessageSync policy value has changed.
Privacy DisableAdvertisingId policy value has changed.
EnterpriseDataProtection (EDP) state has changed.
AllowAppHVSI cached policy has changed.
A NetworkIsolation area policy value has changed.
AppHVSI (Hypervisor-based Virtualized Security Isolation) state has changed.
EdpShowIcons policy value has changed.
The AllowDeviceHealthMonitoring policy value has changed.
AllowWifi policy value changed. SDDL comes from ID_CAP_POLICY_MANAGER and ID_CAP_POLICY_MANAGER_READONLY in %SDXROOT%\src\devmgmt\enterprise\product\policymanager\packages\policymanager.pkg.xml
AllowManualWifiConfiguration policy value changed. SDDL comes from ID_CAP_POLICY_MANAGER and ID_CAP_POLICY_MANAGER_READONLY in %SDXROOT%\src\devmgmt\enterprise\product\policymanager\packages\policymanager.pkg.xml
Allow windows indexer.
AllowWifiDirect policy value changed. SDDL comes from ID_CAP_POLICY_MANAGER and ID_CAP_POLICY_MANAGER_READONLY in %SDXROOT%\src\devmgmt\enterprise\product\policymanager\packages\policymanager.pkg.xml
AllowProjectionToPC policy value changed. SDDL comes from ID_CAP_POLICY_MANAGER and ID_CAP_POLICY_MANAGER_READONLY in %SDXROOT%\src\devmgmt\enterprise\product\policymanager\packages\policymanager.pkg.xml
The AllowMessageMMS policy value has changed.
The AllowMessageRCS policy value has changed.
SMBAutoEncryptedFileExtensions policy value has changed.
Any AppHVSI policy value is changed
The AllowSet24HourClock policy value has changed.
AllowProjectionFromPC policy value changed. SDDL comes from ID_CAP_POLICY_MANAGER and ID_CAP_POLICY_MANAGER_READONLY in %SDXROOT%\src\devmgmt\enterprise\product\policymanager\packages\policymanager.pkg.xml
The ExploitGuard policy values have changed.
The WindowsDefenderSecurityCenter policy values have changed.
Event fired when app privacy policy values have changed
A TextInput EnableTouchKeyboardAutoInvokeInDesktopMode policy value has changed.
A TextInput TouchKeyboardFullModeAvailability policy value has changed.
A TextInput TouchKeyboardWideModeAvailability policy value has changed.
A TextInput TouchKeyboardNarrowModeAvailability policy value has changed.
A TextInput TouchKeyboardHandwritingModeAvailability policy value has changed.
A TextInput TouchKeyboardSplitModeAvailability policy value has changed.
A TextInput TouchKeyboardEmojiButtonAvailability policy value has changed.
A TextInput ForceTouchKeyboardDockedState policy value has changed.
A TextInput TouchKeyboardDictationButtonAvailability policy value has changed.
BITS policy area value has changed.
Removable disk deny write access policy area value has changed.
ETW subsystem initialized
This event signal when a task completion has been revoked due to memory pressure
This event is signaled by the thermal limiter when a power or thermal trip point has been reached that indicates all application views should be closed
This event is signaled by the thermal limiter when a power or thermal trip point has been reached that indicates background tasks should be terminated
This event is signaled by the thermal limiter when a power or thermal trip point has been reached that indicates a warning should be displayed to the user
This event is signaled by the thermal limiter when a power or thermal trip point has been reached that indicates MRC should be stopped
This event is signaled by the thermal limiter when a power or thermal trip point has been reached, which is causing the system to take action to reduce power consumption. The WNF data indicates the number of areas on the device which are being mitigated.
Family Safety settings have changed in the cloud service but have not been downloaded and committed
Family Safety time remaining alerts to warn the user the allocated time is running out. The data is published as json blob with fileds U.SID for User SID as wide character and TR for time remaining in minutes as int value
Family member login event
Family Safety settings have changed and have downloaded and committed. Clients should refresh Family Safety settings.
This event contains a feedback question for the user. Payload is a JSON string specifying the feedback question.
Free network available or not
Triggered every time there is a change in flight IDs
Triggered every time upon WNS notification or policy change
Wait for rundown release in Filter Manager may be blocked by a suspended Modern application
Installation status of Features on demand
This event signals when a tiered volume is mounted
Oplock break acknowledgement may be blocked by a suspended Modern application
This event is signalled when the graphics driver presents the initial frame.
This event is fired for GIP adapter state change, such as connect/disconnect
This event triggers when the user changes Geolocation access for an application or the user.
Do not use this WNF event, it is deprecated. Was WIN32_API_ACCESS_CHANGED.
This event triggers when there is an event that accesses location data -- this trigger starts LocationNotifications.exe which is a systray app.
This is triggered when an app is making use of the location service. It has two possible data values associated to it: BOOL TRUE: one or more applications are using location. BOOL FALSE: no application is using location.
This state is used to notify when the location service starts or stops running
This state is used to notify when the phone location master switch status changes with BOOL as payload. TRUE indicating master switch is ON and FALSE indicating master switch is OFF
This state is used to notify Geofence tracking state for the geofences added by the applications. TRUE if atleast one geofence is actively being tracked and FALSE if there are no geofences being tracked.
Do not use this WNF event, it is deprecated. Was WNF_LFS_BACKGROUND_PERMISSIONCHANGE_STATE
This state is used to notify when a new freely available position can be queried from the location framework.
This state is published whenever the permissions of an active client have changed. Every client on the system receives it, and should run domain-specific logic to see what the impact is (e.g., reconnect location session when permission re-allowed).
This event notifies when the permission regarding the ability to show the location notification icon has changed. The current state needs to be queried for as it is different for each user.
This event notifies when a new action dialog is available
This event notifies when there's a significant change in the location of the device.
This event notifies when there's a visit or a significant change in the location of the device.
This event is fired when an MDM Location policy change occurs.
This event is fired when an MDM EnableLocation policy change occurs.
The user default locale has changed. Subscribers should query for the new value and invalidate any cached date/time or locale sensitive strings.
This state is notified when the User Default UI language (MUI) changes. Subscribers should query Subscribers should query for the new value and invalidate any cached localized resources, strings, other UI related data.
This state is notified when the locale info changes by means of calling SetLocaleInfo. The data value is a DWORD that indicates the LCTYPE that changed.
This state is notified when the user Geo ID (or Geo Name) changes by means of calling SetUserGeoID (or SetUserGeoName). The data value is a DWORD that indicates the new GeoID. (Note: Geo Names should be preferred and used instead of GeoIDs.)
This state is notified when the User Preferred Language List has changed. Subscribers should query GetUserLanguages to get the updated language list.
System policy has been updated
User policy has been updated
This event signals a request to get (if needed) and verify Health Certificate with HAS
Event raised when the display context changes (ex. from physical monitor to HMD). Data contains a DWORD equivalent to Windows::Internal::Shell::Holographic:UserDisplayContext
Event raised when the input context changes (ex. from 3D input to 2D Desktop input). Data contains a DWORD equivalent to Windows::Internal::Shell::Holographic:UserDisplayContext
Event raised when the Holographic Shell running state changes (ex. from Running to Suspended). Data contains a DWORD equivalent to Windows::Internal::Shell::Holographic:ShellState
This event signals when input focus changes to a different window. Data is a MPCInputFocusChange struct.
If payload is non-zero, room boundary is forced to be visible.
This event signals whether streaming is active. Data contains a bool indicating if streaming is active.
This event signals that the persisted room boundary data has changed.
A non-zero payload indicates the room boundary is visible to the user. Writable by DWM and System.
This event signals when various input types should be disabled from natively working in the Windows Holographic shell, useful for apps that simulate GGV via mouse and/or gamepad. Data contains a DWORD of bitflags from Windows::Internal::Shell::Holographic::ShellInput3DSwitchDisableFlags.
This event contains the file path for the environment app's audio asset, which is used by Triton
This event signals that it's time for uninstall preparations, which includes shutting down Oasis apps.
This event signals that uninstall has finished. Data contains a HRESULT representing uninstall success.
This event signals that the shell spawn point should be moved. Data is a DWORD indicating the id of the point that should be set.
Event raised when the Windows Mixed Reality retail demo timer state changes. Data contains a DWORD equivalent to MixedRealityPortal::RetailDemoTimerState.
Event raised when the benchmarked quality level changes. Data contains a DWORD equivalent to Windows::Internal::Shell::Holographic:DisplayQualityState
This event signals that a HoloCoordinator completed uninstall preparation.
System scoped event raised when the display context changes (ex. from physical monitor to HMD). Data contains a DWORD equivalent to Windows::Internal::Shell::Holographic:UserDisplayContext
This event signals the desire to change the HMD use state (the overrideable internal setting, not the physical presence state reported by the HMD). Meant to be used by non-shell inbox applications to trigger the equivalent of the input switch hotkey. Data contains a DWORD equivalent to a bool; true = HmdUseState::InUse, false = HmdUseState::Idle.
This event signals the desire to change the current input foreground to go to the last active 3D window. Meant to be used by non-shell inbox applications to return focus to 3D realm.
This event signals a reset of the holographic idle timer. Writable by DWM and System.
Event raised when the Holographic Shell running state changes on the interactive users session (ex. from Running to Suspended). Data contains a DWORD equivalent to Windows::Internal::Shell::Holographic:ShellState
This event signals whether sharing session is active. Data contains a name of the data provider.
This event signals a miracast projection to establish.
This event signals whether recording is active. Data contains a bool indicating if recording is active.
This state signals NTOS has CPU management privileges in the current partition.
The state of Hyper-V's host-only WMI object provider.
The state of Hyper-V's host-only WMI event provider.
A monitor has changed immersive modes
The immersive launcher's visibility has changed
The monitor the immersive environment is running on has changed. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
User-perceived focus has left an edit box.
Projection display availability has changed
The user experience transparency policy stores the global system transparency policy as a DWORD which contains 0 for disabled and 1 for enabled.
The global/shared lights have changed.
The immersive UI scale has changed for the current session.
Last recorded user activity
Fires if there is new input after track interval.
Cursor Manager is initialized. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
This event signals when the Zephyrus controller has encountered a fault that requires a shell notification.
Embedded mode policy value has changed.
settings for the foreground app and/or iot startup type background tasks have changed
Installation of language features on demand was started (either through Settings or through installation task).
LedAlert settings has changed
A running package's license is now invalid and the package must be suspended or terminated.
A content license's state has been modified.
A root license's state has been modified.
A running optional package's license is lost.
Multi-purpose event for app license notifications.
A offline pc state has been changed.
Licenses have been refreshed.
Failed to launch the modern app because no valid licenses and leases were found
The device license hardware ID is out of tolerance with the device's hardware ID
The hardware ID has changed but is still with in tolerance with the device's hardware ID
A new device license with a different device ID was installed
The device license was uninstalled
The required device license was nout found
The integration device license has expired and can no longer be used to verify or decrypt modern app licenses.
Found a local migrated license which needs to be refereshed with a store signed license.
The MDM Licensing Device Registration Policy has been refreshed.
OS Edition has changed.
OS Policy has changed.
The License Terms can be considered as accepted on this device.
OS will soon notify user of non-genuine state.
Indicates where the ease of access flyout should appear in LogonUI and User Oobe, the data type is RECT. The sddl string grants subscribe and publish permission to both System and Authenticated user accounts
Indicates that a shutdown has been triggered via Slide-to-shutdown. The sddl string grants subscribe and publish permission to both System and Authenticated user accounts
Indicates that user intends to interact with the lock screen (e.g. for Projection or Cortana) and LogonUI should return to the lock screen.
Indicates that the mobile pinpad is visible.
Indicates logon from local console happened, the data type is a GUID which represents the logged-on credential provider CLSID. The sddl string grants subscribe and publish permission to System
This event signals when a credential tile has been selected or deselected.
Indicates that device wake via fingerprint sensor should be disabled. The sddl string grants subscribe and publish permission to both System and Authenticated user accounts, and to App Containers with the userSignInSupport Capability
This event fires when number of bio enrollment app instance changes. The sddl string grants subscribe and publish permission (3) to Authenticated user accounts (AU), Local System (SY), and App containers with the userSignInSupport Capability
Current progress of the MapLoader background engine.
The new status of ODML.
A map package has been added or removed or repositioned in the list.
Sync sets this value to request a wifi probe due to SSL error. SDDL comes from ID_CAP_COMMS_SERVICES in %SDXROOT%\comms\Packages\CommsPlat\Comms.pkg.xml
Interface to Media-UI-request-State mapping for WLAN (802.1x) interfaces
Interface to Media-UI-request-State mapping for LAN (802.3) interfaces
Notification for alerting client apps that the connected account ticketing state has changed
Notification for alerting client apps that the server has reported TPM claims are available in new tickets. Payload is DWORD (enum TpmKeyStateServer) and permanent since it represents device capability needed across reboot.
Notification for alerting client apps about the current client and server TPM state for logging and retry logic. Payload is a struct of two DWORDs (enum TpmKeyStateServer, enum TpmKeyStateClient).
This notification is raised when the memory manager is unable to automatically offline a bad memory page
This notification is raised when the memory manager adds or removes physical memory
Triggered by a monitor device when the thermal limit on brightness is changed. Payload is a MONITOR_THERMAL_BRIGHTNESS_LIMIT_LIST.
This state is notified when the constrast qualifier changed its value. There is nothing in the payload. Subscribers will need to query the qualifier value provider for the latest value. SDDL comes from ID_CAP_EVERYONE and ID_CAP_PM_1ST_PARTY in %SDXMAPROOT%\src\appplat\packages\appplatform\appplatform.pkg.xml
This state is notified when the theme qualifier changed its value. There is nothing in the payload. Subscribers will need to query the qualifier value provider for the latest value. SDDL comes from ID_CAP_EVERYONE and ID_CAP_PM_1ST_PARTY in %SDXMAPROOT%\src\appplat\packages\appplatform\appplatform.pkg.xml
This state is notified when some persistent qualifier changed its value. Payload is qualifier@package_name with a max length of 512 bytes (256 WCHARs including null terminator). Subscribers will need to query the qualifier value provider for the latest value. SDDL comes from ID_CAP_EVERYONE and ID_CAP_PM_1ST_PARTY in %SDXMAPROOT%\src\appplat\packages\appplatform\appplatform.pkg.xml, plus all rights for all containers
This state is notified when system PRI files are merged. Payload has a max length of 128 bytes (64 WCHARs including null terminator) and consists of 'start [starting timestamp]' or 'done [starting timestamp] [ending timestamp]'. SDDL comes from ID_CAP_EVERYONE and ID_CAP_PM_1ST_PARTY in %SDXMAPROOT%\src\appplat\packages\appplatform\appplatform.pkg.xml, plus all rights for all containers
This state is notified when a system PRI file is merged. Payload has a max length of 512 bytes (256 WCHARs including null terminator) and consists of either 'start [path] [starting timestamp]' or '{done,skipped} [path] [starting timestamp] [ending timestamp]'. SDDL comes from ID_CAP_EVERYONE and ID_CAP_PM_1ST_PARTY in %SDXMAPROOT%\src\appplat\packages\appplatform\appplatform.pkg.xml, plus all rights for all containers. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
NaAuth User Presence Status
NaAuth Service Running
NaAuth User Authentication Status
NaAuth Extended Dynamic Lock Status for Bluetooth plugin
NCB indication of CCT or Socket Broker Based App availability.
NDIS finds a network adapter that needs to be configured by NetSetupSvc.
NDIS detects corruption in the binding store.
This event is signalled by rasman about reconnect VPN state change and is used by NLM
This event is signalled by NLM when the aggregated network conditions indicate that a connection to the internet is present
This event is signalled by HNS when it establishes a vNIC which it needs NLM to hide
This state is used to notify that the NFC CE policy changed.
This state is used to notify that the CanMakePayment background broker is initialized and ready.
This event signals when an caller wants to trigger KeyPregenTask.
This event signals when an caller wants to trigger AikCertEnrollTask.
This event is fired when a policy change occurs in the NGC Pro CSP.
This event signals when an caller wants to trigger KeyPregenTask with some delay.
This event signals when NGC container service (ngcctnrsvc) authenticates a gesture.
This event is fired when an MDM cryptographic policy change occurs.
This event is fired when an activity occurs that requires the NGC PIN cred prov to refresh its credential state.
This event is fired when the state has changed during the PIN reset scenario.
This event is fired from the NGC PIN cred prov to signal that the PIN reset scenario should be launched.
Boolean state representing whether or not the Credential Reset User Experience is active.
This event is fired from the NGC PIN cred prov to signal that an Nth user scenario should be launched.
This event triggers the NgcIsoCtnr key pre-gen pool to start generating a key.
This event is notified when NCSI detects a capability change
State name triggering WiFiTask from NlaSvc
This WNF state indicates to users of WPN endpoints (except AppEndpoint) that platform is ready to use. This state can also be used to know if WPN platform restarted.
This WNF state can be used by first party Apps / Services to determine when WPN platform is ready to handle app related requests like posting toast / tile and getting channel uri.
State indicating that system notification platform has been registered and ready to user.
This WNF state indicates that USER_PLATFORM_READY was fired for a user in the current session. This is intended to provide a workaround for the inability to use RtlSubscribeWnfStateChangeNotification for a user other than the current process token. A process can register for this WNF and then poll the per-user WNF states under impersonation.
This notification is to indicate that the NPSM service has started up.
NSI service status. The SDDL grants subscribe access to all who have access to NSI RPC interface and subcribe + publish access to NSI service.
CSC Service start trigger
Triggered every time there is a change in the OneSettings configuration for machine learning model configurations
Triggered every time there is a change in the OneSettings configuration for Velocity feature configurations
Triggered every time there is a change in the OneSettings configuration for Mitigation App configurations
Triggered every time there is a change in the OneSettings configuration for DirectX Database configurations
Triggered every time there is a change in the OneSettings configuration for Muse UX and USO configurations
Triggered every time a feature configuration was completed (as a response to FEATURE_CONFIGURATION_CHANGED)
Notification from ISM to OOBE to query the user whether to activate the always-on Magnifier in OOBE
Notification from OOBE to ISM whether the user confirms to activate the always-on Magnifier in OOBE
Notification to User OOBE monitor on where the progress is
Notification of speech controller state change. Payload is state type plus string of length 512
The window's override scale has changed. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
First Pen Tap Gesture
First Pen Drag Gesture
There is a new persistent memory error.
Sent when the WDI session corresponding to a power scenario changes
Sent when the composite battery is updated. CAPABILITY_SID_VmCapability - S-1-15-3-1024-2268835264-3721307629-241982045-173645152-1490879176-104643441-2915960892-1612460704 (for Hyper-V support)
Sent after WNF_PO_COMPOSITE_BATTERY when batteries are added or removed and when one or more batteries' AC, charging, or discharging states changes
Triggered when Energy Saver state changes. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622
Triggered when Energy Saver setting changes
Triggered to indicate Energy Saver override settings
Triggered to indicate CR3 condition
Sent when the previous shutdown was due to a thermal trip
Sent when the previous hibernate was due to a thermal trip
Estimated time until full discharge in seconds
Filetime of last known start of discharge
Estimated time until full charge in seconds
Triggered to indicate excessive thermal throttling
Sent to indicate whenever user-away prediction is updated.
Sent to indicate whether a display request is active in the current session.
Triggered when battery charge crosses well-known charge level boundaries.
Sent when the global user presence changes.
Unused notification
Triggered when battery is being discharged, irrespective of AC/DC state of the system.
Visible state of the primary display as MONITOR_DISPLAY_STATE
Logical state of the primary display as MONITOR_LOGICAL_DISPLAY_STATE
Sent on every boot to notify previous shutdown state
Triggered at the start of a transition to exit modern standby
Sent when SW DRIPS is more than HW DRIPS by a specific threshold
Sent once platform idle states and associated device constraints have been registered
One time system-wide transition to switch from the basic brightness engine to the high-precision brightness engine.
ALS brightness offset consumed by the basic brightness engine.
Set to TRUE when the video system is initialized.
Notification for power-setting overlay scheme change.
Set when an you want IOCTL_CAD_DISABLE_CHARGING to behave in a sticky manner
Describes the current state of the power button.
Supplies the notification about system time changed. Payload has 2 ULONGLONG for new time and old time.
Triggered when a weak charger is detected. Note that there may be several minute delay between when charger is plugged in and when the notification is produced.
Triggered several minutes prior to idling to sleep.
Triggered when device is sourced from battery(DC) with lid closed and no external monitor connected.
Sent when wake on voice state changes.
Sent to indicate period of opportunistic connectivity in standby.
Describes the input suppression state for modern standby system based on power source, lid state, monitor state, external monitor state and system opted-in policy.
Set to TRUE when one of the battery is in charge limiting mode and FALSE when none of the battery is in charge limiting mode.
Set to TRUE on systems that have a brightness slider that continuously auto-adjusts to the actual brightness of the screen.
This corresponds to a DBT_DEVNODES_CHANGED message
This corresponds to a DBT_DEVNODES_CHANGED message
This corresponds to a drive letter arrival/removal message
This corresponds to a drive letter arrival/removal message
This corresponds to a hardware profiles changed message
This corresponds to a hardware profiles changed message
This corresponds to a ports changes message
This corresponds to a ports changes message
This corresponds to kernel PNP waiting synchronously for user-mode clients
This corresponds to a reboot of the system needs to be performed due to a device installation
Device installation is requested.
A change that requires a device container to be updated has occured.
Fired when a full set of packages are processed.
Fired when TPM, NGC, and MSA all report ready for new tickets to contain the TPM claim. Event contains the HRESULT for the operation.
Fired when an AutoPilot profile is available locally and is non-empty. Event contains the HRESULT for the operation.
Fired when the AutoPilot profile manager completes and is ready to unload.
Fired when the AutoPilot profile manager determines that the MSA client may need to update TPM state
Fired when the Server provisioning in the blocking Device Bootstrap page of commercial OOBE is complete. Data passed in is a DWORD. 0x1, if Bootstrap is complete.
State of boot provisioning tasks. Set to 1 when provisioning is complete. SDDL comes from ID_CAP_PHONEPROVISIONER_EVENTS and PhoneProvisioner in %SDXROOT%\src\devmgmt\dm\packages\provisioning\provisioning.pkg.xml and MvProvisionHost in %SDXROOT%\src\devmgmt\dm\packages\multivariant\multivariant.pkg.xml
Multivariant is ready to deliver SMS messages to RILAdaptation (or any registered recipient)
Multivariant provisioning session status (per slot). Everyone (WD) can subscribe, but just Local System and Admin can publish (SY, BA).
This corresponds to an application that has eclipsed job wake charge resource policy
A WNS notification has been received and the Push To Install service should process it.
This event signals when system radio is changed
This event signals when the client didn't discover SMB1 usage for a specific period
Triggered every time there is a change in Group Policy/ MDM Settings related to Recommended Troubleshooting Privacy Settings
Supplies the current RM memory monitor memory usage metrics. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
Supplies the process ID of the current game mode recipient, or 0 if no recipient is active
Supplies the current quiet mode state as recorded by central resource manager
Supplies the current state of the system as recorded by the system state tracker
This event signals when the RPC firewall manager is initialized
An RPC service trigger has been added or removed
A named pipe service trigger has been added or removed
This event triggers to indicate SCM autostart state
This event signals that there is an update available to the Secure Boot variables.
A notification dialog should be shown to the user.
This event triggers when there is a simple device orientation change. It's data value is one of the SimpleDeviceOrientation enum values. Rights: SensorService can publish, Everyone can subscribe.
This event triggers when the system has completed OOBE (Windows Welcome)
This event triggers when the Uninstall of the system has been disabled
This event signals when the Immersive Shell is started
Set to 0 or more to indicate whether there are any unseen notifications in the notification center. Original SDDL comes from dwm in %SDXROOT%\src\uxplat\MobileUI\Packages\MobileUI\MobileUI.pkg.xml, updated to enable the notification on OneCore
This system-scope event is signaled each time a user's desktop becomes ready. Consider using WNF_SHEL_SESSION_LOGON_COMPLETE for a session-scoped version.
This event signals when logon of the first user after OOBE is complete. Processes with the WINCAP_SHELL_EXPERIENCE_COMPOSER capability are allowed access.
TDL dispatcher pipe has been closed
This event is signalled when there is a tile change to a background task
Event signals when toast notification settings have changed.
This event signals when a SoftLanding rule is triggered
This event signals when Start Experience Host completes loading the Start menu layout
Event signals a full app resolver scan has been invoked.
Set to 0 or 1 to indicate whether the lock screen is active. SDDL follows DEVICE_LOCK_STATE SDDL on skus that don't have multiple sessions, otherwise anyone can read and system can write. Additionally, processes with the WINCAP_CORE_SHELL or WINCAP_SHELL_EXPERIENCE_COMPOSER capability can write.
This event signals when Start Experience Host receives an VISUALELEMENT_EVENT_APPLIFECYCLE_INSTALL_FINISHED event from TDL
This event signals when Start Experience Host receives an VISUALELEMENT_EVENT_APPLIFECYCLE_DOWNLOAD_STARTED event from TDL
Event is for the shell to notify when app layout state is changed. Payload is ShellApplicationStateWnf struct.
This event signals when focus changes to a different process, scoped to System, DWM SID and ID_CAP_INPUT_CORE appcontainer capability and DEFAPPS_CAPABILITY_GROUP SID on Mobile.
This event signals to toggle exclusive gamepad listening on and off, scoped to System, DWM SID and ID_CAP_INPUT_CORE appcontainer capability and DEFAPPS_CAPABILITY_GROUP SID on Mobile.
This event signals to toggle exclusive gamepad input on and off
This even signals when Start layout MDM policy has been applied
Event signals when the apps have been pushed to the indexer has completed
This event signals when SoftLanding rules folder is updated
This event signals that a critical notification such as an incoming call was posted. Original SDDL comes from dwm in %SDXROOT%\src\uxplat\MobileUI\Packages\MobileUI\MobileUI.pkg.xml, updated to enable notification on OneCore
This event signals when Start visibility changes
Set to 0 or 1 to indicate whether the searchbox is visibile in the tray. SDDL follows DEVICE_LOCK_STATE SDDL on skus that don't have multiple sessions, otherwise anyone can read and only system can write.
This event signals that the device is unlocked in the current session
This event signals the changes in places' database (clientgraph)
Event is for the shell to notify when app background activity should be suspended. Payload is DWORD set to 1 or 0.
This event signals a creative event has been triggered
Event signals that the jumplist for an app has changed. Payload is a struct containing the current sessionId as well as a string representing the aumid of the app whose jumplist was updated.
This event signals when Start Experience Host receives an VISUALELEMENT_EVENT_APPLIFECYCLE_UNINSTALL_FINISHED event from TDL
This event signals whenever the nexus button policy changes.
This event signals when a settings toggle has changed
This event signals when a new toast is published
This event signals when a new soft landing tip is published
Event signals when an app requests cortana to build the settings constraint index
This is the state of dictation. SDDL comes from dwm.exe in %SDXROOT%\src\uxplat\MobileUI\Packages\MobileUI\MobileUI.pkg.xml and WPNarrator in %SDXROOT%\src\media\apps\packages\Apps\WPNarrator.pkg.xml. And Phone DefApps group is required too.
This event signals when a parsed command is ready for processing
This event signals when a command has been delivered via WNS
This event signals when a command has been delivered via SMS
This event signals that the device is locked in the current session
This event signals a subscription has been activated.
This event signals the content of one or more subscriptions has been updated.
This event signals that lock screen image had changed. It contains the user sid whose image was changed
Set to 0 (uncovered or unknown) or 1 (covered).
This event signals when connected accounts have changed and register device should be called
This event signals when OOBE in a Shell should enable its provisioning flow
This event signals that the Lock application has been presented to the user. It contains an instance cookie as specified from LogonUI.
This event signals that the Lock application is requesting to unlock so the user can enter credentials.
This event is signalled when there is a tile install to a background task
This event is signalled when there is a tile update to a background task
This event is signalled when there is a tile uninstall to a background task
This event is signalled when there is an app launched (1) or terminated (0) above lock. Processes with the WINCAP_SHELL_EXPERIENCE_COMPOSER capability are allowed full access, while all other app containers have read access.
This event is signalled when the RadialController Experience has restarted to allow registered API component to re-establish connection and repopulate state
This event is signalled when there is bio feedback active (1) or inactive (0) above lock
This event can be signalled when a handsfree device needs to request Cortana to cancel speech activity.
Set to 0 (inactive) or 1 (active).
This event signals a start layout change to a background task so that assets can be retrieved if necessary. Payload is PlaceholderTileWnf.
This event is signalled when there is a change to the Pinned People list
Current lock state of the device. Payload is DEVICE_LOCKSTATE. On multisession SKUs, everyone can read while only SYSTEM can write. On single session SKUs, everyone can read while only DefaultAccount can write. On single session SKUs, also include allow list from the SDDL for DEVICE_LOCK_STATE. Additionally, processes with the WINCAP_CORE_SHELL or WINCAP_SHELL_EXPERIENCE_COMPOSER capability can write.
Event is for the shell to notify when app spatial information has changed. Payload is ApplicationSpatialInformationWnf struct.
Indicates the state of Cortana speech input and output.
This event signals that the LockScreen info is updated.
This event notifies the CDM when a new feature configuration is first used. The SDDL is scoped to AuthenticatedUsers, AppContainers and LPACs (CAPABILITY_SID_LpacAppExperience),MpsSvc
This event is signals when an application launches. The Payload is the appID.
This event is signals when an application is terminated. The Payload is the appID.
This event is signals when a request is made to show a Windows Tip bubble. The Payload is the content id(String).
This event signals when the first time a user is idle after logon. The payload is the time the user has been idled for
This event is signalled when there is a change to the People Pane Views
This event signals that the lock screen should be reset due to a re-lock request.
This event signals that the lock screen is ready after a reset was requested.
This event is scoped to the user session and signaled when the desktop is ready after a logon
This event signals when the health state of the device changes
This event signals that Content Delivery Manager content needs remediation
This event is signals when a desktop application launches. The Payload is the executable name.
This event is signals when a desktop application is terminated. The Payload is the executable name.
This event signals that the app launched by sign in suggestions is ready.
This event is scoped to the user session and signaled when the CDM registration is complete
This event signals that Content Delivery Manager Cache Monitoring is Enabled or not.
Used to signal logon controller across the desktop boundary. Only local system or the composer can read and write. Currently payload is present but ignored.
This event signals when the HidePeopleBar MDM policy has been updated
This event notifies the CDM when a feature configuration is used
This event signals when OOBE in a Shell has completed its provisioning flow. It is permanent since provisioning is only supported during first user OOBE.
This event signals when the signal manager fires a signal
Notification is incremented / signaled when a cloudfile state change is detected by the indexer service. Payload is count of changes. User can subscribe, but only service (indexer) can publish
Notification when a sync client or shell session updates in-memory progress within the indexer service. Payload is the tick count when the last change occurred. User can subscribe, but only service (indexer) can publish
This event signals when Start Experience Host completes a layout migration
This event signals when a Start place MDM policy (AllowPinnedFolder*) has been applied
This event is used by the Signal Manager for WIL Feature Usage subscriptions required by registered signal triggers.
This event signals the current view state of action center.
State of the network as reflected by shell32 listeners. Subscribed to, and published from, explorer.exe, a user process.
This wnf is used for testing purposes.
This event signals for different app install state from the Store. The Payload is the aumId and app state.
CDS restore payload data is downloaded during OOBE
This wnf is signaled everytime the user connects an autoplay device. The payload is the device id (VID and PID).
This wnf is signaled when Cortana's QuietMoment @Home inferred that the user has arrived of left home .
This wnf is signaled everytime the Action Center/Cortana beacon state changes. Payload is an int mapping to an enum representing the new state.
This wnf is signaled whenever active quiet hours profile/mode changes. The value is the restrictive level of an active profile and the restrictive level is unique per profile
This wnf is signaled when WinLogon detects an automatic lock on logon sequence to optimize displaying the user lock screen when the shell is ready.
This wnf indicates for some types of devices if a lid, cover or enclosure around it is closed (zero value) or open (non-zero value).
This event signals a creative event has been triggered that will allow to run during battery saver
This event allows user-mode services such as Windows Notification Platform to determine when Start is suspended
This event signals when a new System Dialog toast is published
This wnf indicates that a variable in the settings environment has changed. The payload is the current sessionId.
This event signals when Quiet Hours mode has changed state in shell
A system-wide unique rolling id for notification controller sink sessions
Event signals Tab Shell component initialization is complete, potentially after an explorer crash. Payload is an incrementing DWORD that can be used to poll if the current objects are new.
Set to 0 or 1 to indicate whether lockapphost is currently active. Anyone (including apps) can read, system has write access (but on multi-session skus authenticated users also have write access). Additionally, processes with the WINCAP_CORE_SHELL or WINCAP_SHELL_EXPERIENCE_COMPOSER capability can write.
This wnf indicates that a cortana capabilties have changed. The payload will be the changed capabilties. The below sids are the CShell compser, cortana app, and cortana test app sids
This event indicates taskbar pins were updated. The SDDL is scoped to AuthenticatedUsers.
This system-scope event is signaled each time the shell attempts to start a local session on WCOS-based SKUs. It carries the latest session ID. Everyone can read from it. Authenticated users can write to it. Apps in general can read from it. Apps with WINCAP_SHELL_EXPERIENCE_COMPOSER can write to it.
This wnf indicates that the assistant state has changed, e.g Talking, idle, thinking, notification pending etc
This event is similar to TOAST_PUBLISHED but at a system rather than session scope
This event signals that a process hosting Action Center has started, such as Shell Experience Host.
This event is fired each time that a signal is registered or unregistered through the SignalRegistration runtime class.
This event signals the suggested content to paste. More details are at https://garagehackbox.azurewebsites.net/hackathons/1235/projects/76296 site.
This event signals that a foreground app changed.
Used to notify the PIN list that a PIN has been enrolled and that it should refresh.
Used to notify the Delay Lock settings that Biometric enrollment has been modified.
A file has changed on storage and a request is received to sync.
A user's quota has changed.
This event triggers when the user revokes SMS access.
This event triggers when the system has multiple memory channels and memory cooling can be started
This notification is issued when a property of an object changes
This notification is issued to request work in user-mode
Indicates the state of the shared recognizer.
Indicates the data pertaining to a remote request to start/stop a speech recognition session. Published by BTAGService and HidSrv. Publish/subscribe granted to btagservice and aarsvc services.
Indicates the KWS request from a remote device. Certain peripherals that support in-built KWS may request the system to disable the KWS runnning on Windows. Published by BTAGService. Publish/subscribe granted to btagservice and aarsvc services.
This event is fired when system administrator change GP and MDM policy which governs capability to connect to speech service.
Sent when a screen on study session starts or ends
This event signals when the server (SRV2) start/stop
This event signals when the server didn't discover SMB1 usage for a specific period
This event indicates a change in the mount state of an SD card.
This event indicates a change in the volume status of an SD card.
This event indicates a change in the free space state of storage.
This event indicates a change in the temp file cleanup state of storage.
This event indicates completion of an update of storage usage categories.
This event informs the system tray that the date-time has changed
This event informs StorSvc that SHSVCS received a device handle event.
This event indicates a change in the app pairing state of an SD card.
Enable the Error Details Cache
The state is published when the system has begun the shutdown or reboot process.
Internet available or not
Free network available or not
SMS has been received
Network state has changed
Radio Operator Message received
Network control channel triggers have been reset
Time zone change
Online ID connected state changed. SDDL comes from ID_CAP_EVERYONE in %SDXROOT%\src\baseos\prod\packages\WLId\WLId.pkg.xml
system is idle or not
System is idle or not
System is domain joined or not
System has booted
System has at least 1 user present
System is AC or DC
Monitor is ON or OFF
IP address is available or not
Indicate a change in the background work cost
Background work cost is high or not
System is in Low Power Epoch or not
Smart card transaction notification. SDDL comes from ID_CAP_NFC_ADMIN in %SDXROOT%\src\net\NFC\packages\product\NFC\NFC.pkg.xml
System is in good state for maintenance
Geolocation service should be started
OEM custom notification received
MO custom notification received
Cached file has updated
Smart card field entry/exit notification. SDDL comes from ID_CAP_NFC_ADMIN in %SDXROOT%\src\net\NFC\packages\product\NFC\NFC.pkg.xml
Smart card HCE application activation notification. SDDL comes from ID_CAP_NFC_ADMIN in %SDXROOT%\src\net\NFC\packages\product\NFC\NFC.pkg.xml
Unused notification
Unused notification
Low-latency power request notification
Resiliency phase notification
Fullscreen video playback notification
Indicates high-performance boost mode for critical NFC background activity
Indicates app launch pre-fetch phase
Unused notification
Indicates app resume phase
Unused notification
Unused notification
Unused notification
Unused notification
Unused notification
Call state change notification
Voicemail change notification
Call history change notification
Phone line change notification
Airplane mode disabled for emergency call notification
Registration state has changed
Radio state has changed
Pin lock state has changed
Device service command has been received
Default Sign In account has changed
Network connectivity in Standby
User presence changed
Audio activity in progress
Fullscreen HDR video playback notification
Indicates UWP app launch phase
Pco data has been received
Mixed reality notification
Game mode scenario
Incoming call dismissed notification
Signals a change caused by SystemParametersInfo(SPI_SETLOGICALDPIOVERRIDE). CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
This is triggered when the Primary monitor's DPI is different than the session's DPI.
The computer has changed density mode. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
Indicates a hotkey was pressed
This is fired every time an SENSE's storage fullness crosses into a new tier or is reset. struct { DWORD PercentageFull[4]; }
This is fired every time an SENSE's daily upload quota crosses into a new tier or is reset. struct { DWORD PercentageFull; }
This is fired every time a onesettings namespace is updated. {UINT64 SettingsCount; struct {UINT64 NamespaceHash; UINT64 TimeLastChanged;}[16]}
This is fired every time a push notification is received from the OneSettings service. UTF8 string.
This is fired every time a UTC service timer changes its configuration values so subscribers can call GetTimerConfiguration to check any new values.
Bitmask containing the current relevant call states. Any 3rd party app is allowed to listen to this. See PhoneWnf.h for valid values. SID referenced below is that of the Phone service.
Bitmask containing the call forwarding state for phone line 0. See PhoneWnf.h for valid values. SDDL comes from PhoneSvc in %SDXROOT%\onecoreuap\net\Phone\PhoneService\Service\lib\Microsoft-Windows-Telephony-Phoneservice.wm.xml
BOOL indicating whether the Phone service has been initialized. SDDL comes from phoneCall and voipCall, PhoneSvc in %SDXROOT%\onecoreuap\net\Phone\PhoneService\Service\lib\Microsoft-Windows-Telephony-Phoneservice.wm.xml
BOOL indicating whether SimSec is ready to receive requests. SDDL comes from ID_CAP_PHONE_2ND_PARTY, ID_CAP_PHONE_INTERNAL and dwm in %SDXROOT%\src\uxplat\MobileUI\Packages\MobileUI\MobileUI.pkg.xml
Wide string indicating the call annotation provider's RPC endpoint name. SDDL comes from ID_CAP_CALLMESSAGING_FILTER and PhoneSvc in %SDXROOT%\onecoreuap\net\Phone\PhoneService\Service\lib\Microsoft-Windows-Telephony-Phoneservice.wm.xml
BOOL indicating whether the line is ready. SDDL comes from PhoneSvc in %SDXROOT%\onecoreuap\net\Phone\PhoneService\Service\lib\Microsoft-Windows-Telephony-Phoneservice.wm.xml
State name for the Tethering service notification of all state changes
State name for starting Tethering service over Bluetooth
Input Mode Indicator label IME want to show on systray. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622
Explicit IME private mode status. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622
Automatic IME private mode status.
short cut(ctrl + shift or alt + shift) pressed.
Notifies when the theme of the system changes. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
Time Zone Legacy store is updated. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
Time Zone store is updated. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
This state is notified when the timezone is changed via SetTimeZoneInformationByID - The data value is a UINT that indicates the new TZID. SDDL comes from ID_CAP_BUILTIN_SETTIME, ID_CAP_EVERYONE and tzautoupdate in %SDXROOT%\src\globplat\product\packages\winnls\winnls.pkg.xml
This event has information about last time sync. SDDL comes from autotimesvc's account.
This event is used to trigger Network Sync. SDDL comes from autotimesvc's account and ID_CAP_BUILTIN_SETTIME in %SDXROOT%\src\media\shell\packages\settings\Settings.pkg.xml
This state is notified when autotimeupdate state changed. The data value is a DWORD that indicates if autotimeupdate is enabled (1) or disabled (0). SDDL comes from autotimesvc's account and ID_CAP_BUILTIN_SETTIME in %SDXROOT%\src\media\shell\packages\settings\Settings.pkg.xml
Touch Event
The touch keyboard's appearance on the screen has changed. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
The restricted mode touch keyboard's appearance on the screen has changed.
An immersive application has encountered a focus change. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
An application encountered a touch down/up event. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
An application encountered a touch down/up event
The active keyboard layout has changed. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
The active keyboard layout has changed. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
Caret tracking has updated on the desktop. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
The autocomplete window has been updated. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
Determines whether focus is in an editable field for the purposes of the modern keyboard. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
The view being shown by the touch keyboard has changed. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
The view being shown by the restricted mode touch keyboard has changed.
The keyboard has recognized a gesture. State is not relevant for this notification and it should not be queried after the fact. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
The restricted keyboard has recognized a gesture. State is not relevant for this notification and it should not be queried after the fact.
The candidate window state has changed. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
The layout being shown by the touch keyboard has changed.
The layout being shown by the restricted mode touch keyboard has changed.
The composition state has changed. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
A System Mode Application(Logon/OOBE) has encountered a focus change
A System Mode application(Logon/OOBE) encountered a touch down/up event
The edit control in focus has changed the input pane display policy (manual/automatic). CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
The system is in desktop mode but the user prefers tablet-mode IHM behavior. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
The touch keyboard should show or hide. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
Update the show/hide status of touch keyboard that is being tracked in tabtip. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
This state name is used to notify system components about state changes in the Token Broker
This state name is used to notify apps about state changes in the Token Broker
This state name is used to notify apps about state changes in the Token Broker
This event signals when the Win32_TPM provider has completed taking ownership of the TPM.
This event signals the state of the TPM-based DeviceID.
This event triggers the TPM provisioning/status check to run.
This event signals a TPM Clear will be attempted.
This event signals if ownership was taken during TPM Provisioning and the result of TPM Clear on last reboot.
This event signals a TPM Disable or TPM Deactivate will be attempted.
This event signals after the TPM is Enabled or Activated.
This event signals the TPM maintenance task status.
The machine power source state
The machine console monitor on/off state
The user is present and machine is on batteries and the battery level is above firmware update thershold
The machine entered pre shutdown phase
Trigger the Driver Manager service start
State name indicating the status of the UMDF driver manager
Signals that a state transition occurred for an update session.
Signals that a state encounter a condition that requires attention.
Signals the a change in progess of an update session.
Signals that a reboot is required to complete the update session.
Signals that the current active session is changed.
Signals that updates have installed successfully on lite servicing stack.
Signals that the machine's up to date status has changed.
Signals that USO should not reboot the system.
Signals that update download has started on lite servicing stack.
Signals that update install has started on lite servicing stack.
Signals various install states on lite servicing stack.
Signals that USO is stopping.
Signals that USO settings have been refreshed.
Signals that USO active hours have started.
A word was added to the User Dictionary. Datasize is the byte count of MAX_PATH + uint32 + BOOL. SDDL SID's come from capability ID_CAP_INPUT_CORE (both application and service SID's), and DefAppsCapabilitiesGroup
A word was added to the User Dictionary. Datasize is the byte count of MAX_PATH + MAX_PATH. SDDL SID's come from capability ID_CAP_INPUT_CORE (both application and service SID's), and DefAppsCapabilitiesGroup
Shell Infrastructure host is ready.
The user was logged in to the system.
The user was logged out of the system.
Default system user, as defined by start view, has changed.
Token for the session user changed.
Session active shell user changed.
The user tile for the specified SID was changed. The payload is the String user sid and the datasize is the byte count of MAX_PATH.
The UWF overlay consumption is at warning level.
The UWF overlay consumption is at critical level.
The UWF overlay consumption is at normal level.
The VAN UI open close status
Notification for syncing CDS WebCredential store
Notification for New Credential Added
The VPN Client connectivity status. SDDL gives RasMan read/write permissions, rescap:networkingVpnProvider read permissions, and Authenticated User read permissions.
WaaS Assessment Impact level for quality update
WaaS Assessment Impact level for feature update
This event signals when a WCM-managed network interface has been added or removed
Connection Manager service restart
WNF state for refreshing WCM service mapping policies cache
WNF state for refreshing WCM's selection multiplex table and selectable connection list
This event signals when a WCM-managed network interface has changed its connection quality state
the data of this state is 1 when the global data usage state is less than or equal to OVER_LIMIT, otherwise it is 0
the data of this state is 1 when the global data usage state is less than or equal to OFF_TRACK, otherwise it is 0
the data of this state is 1 when the global data usage state is less than or equal to ON_TRACK, otherwise it is 0
the data of this state is 1 when the global data usage state is less than or equal to UNDER_TRACK, otherwise it is 0
the data of this state is 1 when the global data usage state is less than or equal to NOT_TRACKED, otherwise it is 0
State name for Cellular connections available State. SDDL comes from WcmSvc service in %SDXROOT%\src\net\NetCore\Packages\NetCore\NetCore.pkg.xml
The state is 1 when a non cellular connection is in connected state, otherwise it is 0. SDDL comes from WcmSvc service in %SDXROOT%\src\net\NetCore\Packages\NetCore\NetCore.pkg.xml
The state is 1 when Radio is active or a non cellular connection is in connected state, otherwise it is 0. SDDL comes from WcmSvc service in %SDXROOT%\src\net\NetCore\Packages\NetCore\NetCore.pkg.xml
The state is 1 when Cellular data is active, otherwise it is 0. SDDL grants read access for everyone, including AppContainers, and write access for System
The state is 1 when WiFi is active, otherwise it is 0. SDDL grants read access for everyone, including AppContainers, and write access for System
Trigger task scheduler to launch task for toast
The state is 1 when cellular internet connection is not allowed to any UWP Application running in background, the state is 0 when cellular internet connection is allowed to any applications running in foreground or background.
A Settings for WDAG requiring the user context has changed.
A Settings for WDAG requiring system context has changed.
This is fired every time the WDATP Cloud service has a new command. struct {UINT64 TimeLastChanged;}
This event triggers a refresh for the account pillar state
This event signals CTAP device state changes.
This event signals CTAP device was inserted or tapped.
The WER service needs to start. CAPABILITY_SID_LpacInstrumentation - S-1-15-3-1024-3153509613-960666767-3724611135-2725662640-12138253-543910227-1950414635-4190290187
The number of reports queued to the machine store. CAPABILITY_SID_LpacInstrumentation - S-1-15-3-1024-3153509613-960666767-3724611135-2725662640-12138253-543910227-1950414635-4190290187
Information about applications currently crashing.
State name for Wifi radio and connection status flags. SDDL comes from WcmSvc service in %SDXROOT%\src\net\NetCore\Packages\NetCore\NetCore.pkg.xml
State name for Wifi CPL status flags
Notifications received from the WiFi Conn Svc. SDDL comes from WcmSvc service in %SDXROOT%\src\net\NetCore\Packages\NetCore\NetCore.pkg.xml
State name for Wifi Hotspot Host ready flags. SDDL comes from WcmSvc service in %SDXROOT%\src\net\NetCore\Packages\NetCore\NetCore.pkg.xml
State name for Wifi power status flags. SDDL comes from WcmSvc service in %SDXROOT%\src\net\NetCore\Packages\NetCore\NetCore.pkg.xml
State name for Wifi connection status and connection score updates
State name for Wifi network tiles updated. SDDL comes from WcmSvc service in %SDXROOT%\src\net\NetCore\Packages\NetCore\NetCore.pkg.xml
Average peak transmitted traffic seen by NCSI
Last media streaming mode state change
State name triggering WiFiNetworkManager background task. SDDL comes from WcmSvc service in %SDXROOT%\src\net\NetCore\Packages\NetCore\NetCore.pkg.xml
State for triggering browser UI when a network is hijacked. SDDL comes from WcmSvc service in %SDXROOT%\src\net\NetCore\Packages\NetCore\NetCore.pkg.xml
This event sends notifications from wlansvc
State name for triggering hotspot2 registration status from online signup server
Signals that the Wi-Fi stack is handling an important scenario which must be protected from disruptive activity such as unexpected scans, or activity on a shared radio.
Event indicating that the user may have moved to a different location based on nearby AP RSSI and other signals. Value is a counter indicating how many times movement has been detected.
State name for starting the WLAN scheduled task.
Reports properties about a Wi-Fi Display disconnect
Event indicating that the user may have moved to a different location during the Infracast session. Value is a counter indicating how many times movement has been detected.
Event indicating the current state of the infra walk-away listener. 0: Listening, 1: User elected to stay connected, 2: Auto Disconnect was triggered, 3: Session ended without triggering movement detection.
Event indicating the Normal feature store has been modified. SDDL comes from featureStagingInfo in %SDXROOT%\onecore\base\wil\mbs\Microsoft-Windows-Internal-Libraries-Capabilities\wil.wm.xml
Event indicating the Boot feature store has been modified. SDDL comes from featureStagingInfo in %SDXROOT%\onecore\base\wil\mbs\Microsoft-Windows-Internal-Libraries-Capabilities\wil.wm.xml
Event to indicate the first use of a feature on this device (1). CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622. DPS service SID: S-1-5-80-2970612574-78537857-698502321-558674196-1451644582.
Event to indicate the first use of a feature on this device (2). CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622. DPS service SID: S-1-5-80-2970612574-78537857-698502321-558674196-1451644582.
Event to indicate the first use of a feature on this device (3). CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622. DPS service SID: S-1-5-80-2970612574-78537857-698502321-558674196-1451644582.
Event to indicate unique use of a feature on this device (1). CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622. DPS service SID: S-1-5-80-2970612574-78537857-698502321-558674196-1451644582.
Event to indicate unique use of a feature on this device (2). CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622. DPS service SID: S-1-5-80-2970612574-78537857-698502321-558674196-1451644582.
Event to indicate unique use of a feature on this device (3). CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622. DPS service SID: S-1-5-80-2970612574-78537857-698502321-558674196-1451644582.
Event to indicate uniquely observed code failures on this device (1). CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622. DPS service SID: S-1-5-80-2970612574-78537857-698502321-558674196-1451644582.
Event to indicate uniquely observed code failures on this device (2). CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622. DPS service SID: S-1-5-80-2970612574-78537857-698502321-558674196-1451644582.
Event to indicate uniquely observed code failures on this device (3). CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622. DPS service SID: S-1-5-80-2970612574-78537857-698502321-558674196-1451644582.
Event to indicate uniquely observed code failures on this device (4). CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622. DPS service SID: S-1-5-80-2970612574-78537857-698502321-558674196-1451644582.
Event to indicate uniquely observed code failures on this device (5). CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622. DPS service SID: S-1-5-80-2970612574-78537857-698502321-558674196-1451644582.
Event to indicate uniquely observed code failures on this device (6). CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622. DPS service SID: S-1-5-80-2970612574-78537857-698502321-558674196-1451644582.
Event indicates modification of the WIL Machine feature store. SDDL comes from featureStagingInfo in %SDXROOT%\onecore\base\wil\mbs\Microsoft-Windows-Internal-Libraries-Capabilities\wil.wm.xml. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622. DPS service SID: S-1-5-80-2970612574-78537857-698502321-558674196-1451644582.
Event fires once per boot on modification of the WIL Machine feature store. SDDL comes from featureStagingInfo in %SDXROOT%\onecore\base\wil\mbs\Microsoft-Windows-Internal-Libraries-Capabilities\wil.wm.xml. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622. DPS service SID: S-1-5-80-2970612574-78537857-698502321-558674196-1451644582.
Event indicates modification of the WIL User feature store. SDDL comes from featureStagingInfo in %SDXROOT%\onecore\base\wil\mbs\Microsoft-Windows-Internal-Libraries-Capabilities\wil.wm.xml. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622. DPS service SID: S-1-5-80-2970612574-78537857-698502321-558674196-1451644582.
Event fires once per user session on modification of the WIL User feature store. SDDL comes from featureStagingInfo in %SDXROOT%\onecore\base\wil\mbs\Microsoft-Windows-Internal-Libraries-Capabilities\wil.wm.xml. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622. DPS service SID: S-1-5-80-2970612574-78537857-698502321-558674196-1451644582.
Event indicates there is unique and custom usage of a feature. This is for SRUM consumption. DPS service SID: S-1-5-80-2970612574-78537857-698502321-558674196-1451644582
This event is fired when an enrollment completes, either successfully, or unsuccessfully.
Triggered each time there is a configuration change in WinRE
This WNF event fires when the OEM, MO, and Device Hardware values change in the registry.
This WNF event fires when the MO discovery task state changes. It will send an 0x00000000 if not running and 0x00000001 if running.
This WNF event fires when the OEM discovery task state changes. It will send an 0x00000000 if not running and 0x00000001 if running.
State stores the number of per-user updates for the current user
Triggered each time an AU scan is completed
State stores information regarding WU call hangs
State stores information regarding WU service hangs
Triggered when a StageUpdate call has completed for a phone update installation.
Indicates an update will expire on the next WU service scavenge task. The data type is a GUID which represents the update ID.
A network proxy has been discovered. WinHttpAutoProxySvc can write, NlaSvc can read.
A proxy has returned a 407 status code.
Mirrors the state of CEIPEnable and CEIPSampledIn registry settings.
The WNS Connection Provider connectivity status
Overlay configuration change
System sharing status changed
ICS DHCP IPv4 lease list changed
New assigned Fast-IP Address(es)
This is the current stream state of a camera for a process in a given session
This is the current device state
This is stream activity indicator
This is stream activity indicator
This is user global camera privacy state indicator when switched via physical button
Time Broker has finished processing a change ot time
BOOL + UserContextToken indicating whether the UserDataService service has been initialized for the specified user. On OneCore, SDDL gives read access to callers with userDataSystem/userDataSystem capablity group and all access to IU/AU/System. On phone, SDDL comes from ID_CAP_APPOINTMENTS, ID_CAP_COMMS_COMMON, ID_CAP_CONTACTS, ID_CAP_EVERYONE, ID_CAP_PLATFORM_EXTENSIBILITY, UserDataSvc and ID_CAP_SMS in %SDXROOT%\comms\Packages\CommsPlat\Comms.pkg.xml
State name for aggregate sort and display order changes. SDDL comes from ID_CAP_COMMS_APPLICATIONS and ID_CAP_COMMS_SERVICES in %SDXROOT%\comms\Packages\CommsPlat\Comms.pkg.xml
The application specific context has changed in steady state. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
The currently focused application has changed. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
An application is activating.
The currently focused application component has changed.
A new toast notification has been delivered to the shell.
A package is about to be unmounted from the System OS ready to launch it on the Title OS.
A new application package has been added or an existing one has been removed.
Idle dimmer has changed state.
An application package has been removed.
An application is no longer running.
An optical disc or other media has been detected with content.
Application error handler
Handler for achievement cache and game save storage
Connectivity to the Xbox LIVE service has changed.
System Title Authentication status has changed.
A new achievements-related raw notifications was received.
ERA VM status has changed.
One or more application layouts changed.
System Idle Timeout has changed.
System constrained status has changed. CAPABILITY_SID_LpacMedia - S-1-15-3-1024-1692970155-4054893335-185714091-3362601943-3526593181-1159816984-2199008581-497492991.
Application's COM resiliency status has changed.
Default system user, as defined by start view, has changed. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
A storage device was either plugged or unplugged.
The system is exiting silent boot mode.
The license used by the application has changed.
The system shell is initialized and ready.
Pass 3 system update has progressed and is sending a notification.
The MSA and WNS environments have been configured to match the XBL environment.
The visibility of the Software Input Pane has changed. CAPABILITY_SID_LpacAppExperience - S-1-15-3-1024-1502825166-1963708345-2616377461-2562897074-4192028372-3968301570-1997628692-1435953622.
Game streaming state has changed.
It is possible to transfer focus away from the Software Input Pane.
SMB shares have been launched.
A snap of XBBlackbox has occurred
Maintenance work is allowed in low power mode
ERA launch notification with XBL title info
Status of attached storage devices
A storage device, or its contents, have changed
Current state of the streaming package
The install streaming queue contents have changed
An update is available for installing content.
A change has been made to the pre-indexed state repository.
The number of LiveTV tuners connected to the system has changed
A change has been made to the package cache.
The WPN platform host is initialized and ready.
The rectangle visual of the Narrator has changed.
A package is about to be unmounted from the System OS for uninstall.
A module requested for an ltv command to be issued.
An entity has changed in the shell data cache.
The visibility of the Cortana Overlay view has changed.
Number of unread notifications for the current system user.
Extended resource mode has been toggled
Indicates whether the shell is in the process of auto-signin. Payload is UINT32 with a 1 or 0.
A local user has signed out remotely via SPOP.
Indicates whether the Narrator is enabled. Payload is UINt32 with 1 (enabled) or 0 (disabled).
A global speech command was recognized that translates to a controller button press.
The current user of the application has changed.
ERA VM Instance has come up or gone down
Idle monitor timer should be reset due to user activity.
Notification for when TV grammars for cortana needs rebuilding
Notification for when signed in users change results in rebuilding grammars for cortana
An application that requires Kinect has connected to the NuiService.
Adjust an app's CPU affinity if in constrained mode
The active shared video player host has changed.
The video player app has changed internal state.
The video player app has changed playback progress.
Indicates whether the safe area setting is enabled. Payload is UINT32 with a 1 or 0.
The application providing audio from the background has changed.
Indicates that the desired keyboard locale has changed.
The local gamer account has signed in or out. Payload is uint32 representing sessionid
ERA VM IO priority has been changed
Input device changed for OneCore speech
Notification for when the active user of Cortana changes from signing in/out/switching user
The exclusive input modality for an accessibility component changed
Proactive notification service is triggered
Notification for when the Achievement Tracker's state should change
Event to trigger direct activation of xbox guide when nexus is pressed
A title SPOP veto has been received.
A new library-related raw notifications was received.
A new messaging-related raw notifications was received.
A new people-related raw notifications was received.
A new multiplayer-related raw notifications was received.
A new live tv-related raw notifications was received.
A new SystemUI-related raw notifications was received.
A new club-related raw notifications was received.
A new club chat-related raw notifications was received.
A new settings-related raw notifications was received.
Notification of whether any media is playing.
An expandedResources app has gone inactive.
The maximum age rating currently permissable has changed.
Notification for when the Party Overlay's state should change
A cloud settings collection was updated
ERA Fast Iteration Mode has changed.
The Network Transfer Manager's constrained mode changed.
Narrator input learning mode changed.
Initialization of the skeletal tracking pipeline should be suspended / resumed.
Immersive background or connected animation setting changed.
Copy on LAN upload state has changed.
Event to trigger direct activation of xbox dashboard.
A new Command Service raw notification was received.
A notification settings was updated
A new guest VM crash dump file was written.
User initiated network connection test has completed with no errors
GameCore launch notification with title info
XVC corruption has been detected.
ERA title has presented its first frame.
Indicates whether there are any enrolled users.
Triggered when the lock screen is dismissed to kick-off trusted signals.
This event indicates the state of a USB Type-C connector's partner device.
This event indicates that the number of Billboard devices in the system has changed.
This is the state of a peer device.
This event indicates the USB charging state for this Windows device.
This event indicates the state of a USB function controller, such as detached, or attached, and successfully enumerated with host PC.
This event indicates that a USB error notification needs to be published.
This indicates that the hub collection in USB Policy Manager has changed.
This event indicates the state of a USB XHCI controller's audio offload state.
Комментариев нет:
Отправить комментарий