<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v3" manifestVersion="1.0" copyright="Copyright (c) Microsoft Corporation. All Rights Reserved." xmlns:xsd="http://www.w3.org/2001/XMLSchema">
  <assemblyIdentity name="Microsoft-Windows-LSA" version="10.0.26100.8655" processorArchitecture="amd64" language="neutral" buildType="release" publicKeyToken="31bf3856ad364e35" versionScope="nonSxS" />
  <dependency discoverable="no" resourceType="resources">
    <dependentAssembly>
      <assemblyIdentity name="Microsoft-Windows-LSA.Resources" version="10.0.26100.8655" processorArchitecture="amd64" language="*" buildType="release" publicKeyToken="31bf3856ad364e35" />
    </dependentAssembly>
  </dependency>
  <file name="lsasrv.dll" destinationPath="$(runtime.system32)\" sourceName="lsasrv.dll" importPath="$(build.nttree)\" sourcePath=".\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transforms>
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue>tkOk6CedSF2t1qsb5IA05zY0JmFuT7rzOkBRsOUSzQ4=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <file name="lsaadt.dll" destinationPath="$(runtime.system32)\" sourceName="lsaadt.dll" importPath="$(build.nttree)\" sourcePath=".\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transforms>
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue>B3T8uMdb22rmwOLP+m6vsQTSlsJsJq9gT7O6QsyvLfQ=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <file name="ksecpkg.sys" destinationPath="$(runtime.drivers)\" sourceName="ksecpkg.sys" importPath="$(build.nttree)\" sourcePath=".\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transforms>
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue>r8Loq7D3DK9HTqlaHGe/zM1fPSmnFRaqWk1U74GgjX4=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <file name="Kerb3961Kernel.sys" destinationPath="$(runtime.drivers)\" sourceName="Kerb3961Kernel.sys" importPath="$(build.nttree)\" sourcePath=".\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transforms>
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue>nuvrOvdLHiHOX51Kpz4EMXXbnv1CsLatcJUzlnDZNQg=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <file name="offlinelsa.dll" destinationPath="$(runtime.system32)\" sourceName="offlinelsa.dll" importPath="$(build.nttree)\" sourcePath=".\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transforms>
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue>0qo8Fx4IGjZuO0jMaWNcee/ENlGjm0N80FdLbJpJLSc=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <directories />
  <registryKeys>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LsaExtensionConfig\LsaSrv">
      <registryValue name="Extensions" valueType="REG_MULTI_SZ" value="&quot;lsasrv.dll&quot;" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LsaExtensionConfig\Interfaces">
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LsaExtensionConfig\Interfaces\1001">
      <registryValue name="Extension" valueType="REG_SZ" value="lsasrv.dll" />
      <registryValue name="Name" valueType="REG_SZ" value="LsaLsasrvInterface" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LsaExtensionConfig\Interfaces\1002">
      <registryValue name="Extension" valueType="REG_SZ" value="dpapisrv.dll" />
      <registryValue name="Name" valueType="REG_SZ" value="LsaDpapiInterface" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\CentralizedAccessPolicies">
      <registryValue name="MaxDataSize" valueType="REG_DWORD" value="0x00000000" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\CentralizedAccessPolicies\CAPs" />
    <registryKey keyName="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\CentralizedAccessPolicies\CAPEs" />
    <registryKey keyName="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\OSConfig">
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\UBPM\{5b004607-1087-4f16-b10e-979685a8d131}">
      <registryValue name="LoggerName" valueType="REG_SZ" value="UBPM" />
      <registryValue name="Enabled" valueType="REG_DWORD" value="0x00000001" />
      <registryValue name="EnableLevel" valueType="REG_DWORD" value="0x00000000" />
      <registryValue name="EnableFlags" valueType="REG_DWORD" value="0x00FFFFFF" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data">
      <securityDescriptor name="LSA_MUTABLE_REGISTRY_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG">
      <securityDescriptor name="LSA_MUTABLE_REGISTRY_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD">
      <securityDescriptor name="LSA_MUTABLE_REGISTRY_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1">
      <securityDescriptor name="LSA_MUTABLE_REGISTRY_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security">
      <registryValue name="5b004607-1087-4f16-b10e-979685a8d131" valueType="REG_BINARY" value="01000480300000003c000000000000001400000002001c000100000000001400ff0f1200010100000000000512000000010100000000000512000000010100000000000512000000" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\OfflineLSA\DBOptions">
      <securityDescriptor name="LSA_MUTABLE_REGISTRY_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\OfflineSAM\DBOptions">
      <securityDescriptor name="LSA_MUTABLE_REGISTRY_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\ComponentUpdates\Privileges">
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Tracing">
      <securityDescriptor name="LSA_MUTABLE_REGISTRY_SDDL" />
    </registryKey>
  </registryKeys>
  <memberships>
    <categoryMembership>
      <id name="Microsoft.Windows.Categories.Services" version="10.0.26100.8655" publicKeyToken="31bf3856ad364e35" typeName="Service" />
      <categoryInstance subcategory="KSecPkg">
        <serviceData name="KSecPkg" errorControl="critical" start="boot" type="kernelDriver" group="Cryptography" imagePath="System32\Drivers\ksecpkg.sys" tag="2" />
      </categoryInstance>
    </categoryMembership>
    <categoryMembership>
      <id name="Microsoft.Windows.Categories" version="1.0.0.0" publicKeyToken="365143bb27e7ac8b" typeName="BootCritical" />
    </categoryMembership>
    <categoryMembership>
      <id name="Microsoft.Windows.Categories" version="1.0.0.0" publicKeyToken="365143bb27e7ac8b" typeName="BootRecovery" />
    </categoryMembership>
  </memberships>
  <asmv2:configuration xmlns:asmv2="urn:schemas-microsoft-com:asm.v3" xmlns:wcm="http://schemas.microsoft.com/WMIConfig/2002/State">
    <asmv2:configurationSchema>
      <xsd:schema xmlns="Microsoft-Windows-LSA" targetNamespace="Microsoft-Windows-LSA">
        <xsd:element default="&quot;&quot;" name="Security_Packages" type="wcm:multiString" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyName="Security Packages" wcm:legacyType="REG_MULTI_SZ" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="LsaLookupCacheRefreshTime" type="xsd:unsignedInt" wcm:description="Contains the time (in minutes) when each entry of the LSA lookup cache needs refreshing" wcm:displayName="LSA lookup cache refresh time (in minutes)" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="LsaLookupCacheExpireTime" type="xsd:unsignedInt" wcm:description="Contains the time (in minutes) when each entry of the LSA lookup cache expires" wcm:displayName="Lsa lookup cache expire time (in minutes)" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="LsaLookupCacheMaxSize" type="xsd:unsignedInt" wcm:description="Contains the maximum number of entries LSA lookup cache" wcm:displayName="Lsa lookup cache max size" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="LookupLogLevel" type="xsd:unsignedInt" wcm:description="Contains the setting for LSA lookup log level" wcm:displayName="LSA lookup log level" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="LsaLookupReturnSidTypeDeleted" type="xsd:boolean" wcm:description="Contains the setting for allowing NT4 clients to receieve SidTypeDeleted instead of SidTypeUnknown if the domain of the account can be found, but the account cannot be found during sid lookups" wcm:displayName="Return sid type deleted for unknown accounts for requests from NT4 clients" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="LsaLookupRestrictIsolatedNameLevel" type="xsd:boolean" wcm:description="Contains the setting for allowing chaining of lookup requests to external trusted domains if isolated names are used" wcm:displayName="Do not allow chaining of lookup requests to external trusted domains if isolated names are used" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="LspDbgInfoLevel" type="xsd:unsignedInt" wcm:description="Contains the setting of logging level for LSA Policy operations" wcm:displayName="Logging level for LSA Policy operations" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="LspDbgTraceOptions" type="xsd:unsignedInt" wcm:description="Contains the setting of logging options for LSA Policy operations" wcm:displayName="Logging options for LSA Policy operations" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
      </xsd:schema>
    </asmv2:configurationSchema>
  </asmv2:configuration>
  <trustInfo>
    <security>
      <accessControl>
        <securityDescriptorDefinitions>
          <securityDescriptorDefinition name="WRP_PARENT_DIR_DEFAULT_SDDL" sddl="O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:P(A;CI;GA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;0x1301bf;;;SY)(A;IOCIOI;GA;;;SY)(A;;0x1301bf;;;BA)(A;IOCIOI;GA;;;BA)(A;CIOI;GRGX;;;BU)(A;OICIIO;GA;;;CO)(A;CIOI;GRGX;;;S-1-15-2-1)(A;CIOI;GRGX;;;S-1-15-2-2)" operationHint="replace" />
          <securityDescriptorDefinition name="WRP_REGKEY_DEFAULT_SDDL" sddl="O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:P(A;CI;GA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;CI;GR;;;SY)(A;CI;GR;;;BA)(A;CI;GR;;;BU)(A;CI;GR;;;S-1-15-2-1)(A;CI;GR;;;S-1-15-3-1024-1065365936-1281604716-3511738428-1654721687-432734479-3232135806-4053264122-3456934681)" operationHint="replace" />
          <securityDescriptorDefinition name="LSA_MUTABLE_REGISTRY_SDDL" sddl="O:BAG:SYD:PAI(A;CIIO;GA;;;CO)(A;CI;GA;;;SY)(A;CI;GA;;;BA)" operationHint="replace" />
          <securityDescriptorDefinition name="WRP_FILE_DEFAULT_SDDL" sddl="O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:P(A;;FA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;GRGX;;;BA)(A;;GRGX;;;SY)(A;;GRGX;;;BU)(A;;GRGX;;;S-1-15-2-1)(A;;GRGX;;;S-1-15-2-2)S:(AU;FASA;0x000D0116;;;WD)" operationHint="replace" description="Default SDDL for Windows Resource Protected file" />
        </securityDescriptorDefinitions>
      </accessControl>
    </security>
  </trustInfo>
  <WinsockAppPermittedLspCategories Path="%SystemRoot%\system32\lsass.exe" PermittedLspCategories="0x40000000" />
  <instrumentation>
    <counters xmlns="http://schemas.microsoft.com/win/2005/12/counters" schemaVersion="2.0">
      <provider applicationIdentity="%systemroot%\system32\lsasrv.dll" providerGuid="{d1d20539-be21-4f85-a431-b1d6623a71d4}" providerType="userMode" symbol="PerfCounterProvider">
        <counterSet description="These counters track the number of security resources and handles used per process." descriptionID="55002" guid="{fabd0f84-cead-4e91-925f-1b17a289bb48}" instances="multiple" name="Security Per-Process Statistics" nameID="55000" symbol="PerfCounterPerProcess" uri="Microsoft.Windows.System.PerfCounters.SecurityPerProcess">
          <counter description="This counter tracks the number of credential handles in use by a given process.  Credential handles are handles to pre-existing credentials, such as a password, that are associated with a user and are established through a system logon." descriptionID="55006" detailLevel="standard" id="0" name="Credential Handles" nameID="55004" symbol="PerfCounterCredHandles" type="perf_counter_rawcount" uri="Microsoft.Windows.System.PerfCounters.SecurityPerProcess.CredentialHandles" />
          <counter description="This counter tracks the number of context handles in use by a given process.  Context handles are associated with security contexts established between a client application and a remote peer." descriptionID="55010" detailLevel="standard" id="1" name="Context Handles" nameID="55008" symbol="PerfCounterContextHandles" type="perf_counter_rawcount" uri="Microsoft.Windows.System.PerfCounters.SecurityPerProcess.ContextHandles" />
        </counterSet>
        <counterSet description="These counters track authentication performance on a per second basis." descriptionID="56002" guid="{4d5a21bb-6a86-4a7f-8fc3-4b79d7f9a74f}" instances="single" name="Security System-Wide Statistics" nameID="56000" symbol="PerfCounterSystemWide" uri="Microsoft.Windows.System.PerfCounters.SecuritySystemWide">
          <counter description="This counter tracks the number of NTLM authentications processed per second for the AD on this DC or for local accounts on this member server." descriptionID="56006" detailLevel="standard" id="0" name="NTLM Authentications" nameID="56004" symbol="PerfCounterNTLMAuth" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.SecuritySystemWide.NTLMAuth" />
          <counter description="This counter tracks the number of times that clients use a ticket to authenticate to this computer per second." descriptionID="56010" detailLevel="standard" id="1" name="Kerberos Authentications" nameID="56008" symbol="PerfCounterKerbAuth" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.SecuritySystemWide.KerbAuth" />
          <counter description="This counter tracks the number of Authentication Service (AS) requests that are being processed by the Key Distribution Center (KDC) per second. Clients use AS requests to obtain a ticket-granting ticket." descriptionID="56014" detailLevel="standard" id="2" name="KDC AS Requests" nameID="56012" symbol="PerfCounterKdcAS" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.SecuritySystemWide.KdcAS" />
          <counter description="This counter tracks the number of ticket-granting service (TGS) requests that are being processed by the Key Distribution Center (KDC) per second. Clients use these TGS requests to obtain a service ticket, which allows a client to access resources on other computers." descriptionID="56018" detailLevel="standard" id="3" name="KDC TGS Requests" nameID="56016" symbol="PerfCounterKdcTGS" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.SecuritySystemWide.KdcTGS" />
          <counter description="This counter tracks the number of Secure Sockets Layer (SSL) entries that are currently stored in the secure channel (Schannel) session cache.  The Schannel session cache stores information about successfully established sessions, such as SSL session IDs.  Clients can use this information to reconnect to a server without performing a full SSL handshake." descriptionID="56022" detailLevel="standard" id="4" name="Schannel Session Cache Entries" nameID="56020" symbol="PerfCounterSSLCache" type="perf_counter_rawcount" uri="Microsoft.Windows.System.PerfCounters.SecuritySystemWide.SSLCache" />
          <counter description="This counter tracks the number of Secure Sockets Layer (SSL) entries that are currently stored in the secure channel (Schannel) session cache and that are currently in use.  The Schannel session cache stores information about successfully established sessions, such as SSL session IDs.  Clients can use this information to reconnect to a server without performaing a full SSL handshake." descriptionID="56026" detailLevel="standard" id="5" name="Active Schannel Session Cache Entries" nameID="56024" symbol="PerfCounterSSLActiveCache" type="perf_counter_rawcount" uri="Microsoft.Windows.System.PerfCounters.SecuritySystemWide.SSLActiveCache" />
          <counter description="This counter tracks the number of Secure Sockets Layer (SSL) full client-side handshakes that are being processed per second.  During a handshake, signals are exchanged to acknowledge that communication can occur between computers or other devices." descriptionID="56030" detailLevel="standard" id="6" name="SSL Client-Side Full Handshakes" nameID="56028" symbol="PerfCounterSSLClientFull" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.SecuritySystemWide.SSLClientFull" />
          <counter description="This counter tracks the number of Secure Sockets Layer (SSL) client-side reconnect handshakes that are being processed per second.  Reconnect handshakes allow session keys from previous SSL sessions to be used to resume a client/server connection, and they require less memory to process than full handshakes." descriptionID="56034" detailLevel="standard" id="7" name="SSL Client-Side Reconnect Handshakes" nameID="56032" symbol="PerfCounterSSLClientReconnect" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.SecuritySystemWide.SSLClientReconnect" />
          <counter description="This counter tracks the number of Secure Sockets Layer (SSL) full server-side handshakes that are being processed per second.  During a handshake, signals are exchanged to acknowledge that communication can occur between computers or other devices." descriptionID="56038" detailLevel="standard" id="8" name="SSL Server-Side Full Handshakes" nameID="56036" symbol="PerfCounterSSLServerFull" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.SecuritySystemWide.SSLServerFull" />
          <counter description="This counter tracks the number of Secure Sockets Layer (SSL) server-side reconnect handshakes that are being processed per second.  Reconnect handshakes allow session keys from previous SSL sessions to be used to resume a client/server connection, and they require less memory to process than full handshakes." descriptionID="56042" detailLevel="standard" id="9" name="SSL Server-Side Reconnect Handshakes" nameID="56040" symbol="PerfCounterSSLServerReconnect" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.SecuritySystemWide.SSLServerReconnect" />
          <counter description="This counter tracks the number of Digest authentications that are being processed per second." descriptionID="56046" detailLevel="standard" id="10" name="Digest Authentications" nameID="56044" symbol="PerfCounterDigestAuth" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.SecuritySystemWide.DigestAuth" />
          <counter description="This counter tracks the number of Kerberos requests that a read-only domain controller (RODC) forwards to its hub, per second.  This counter is tracked only on a RODC." descriptionID="56050" detailLevel="standard" id="11" name="Forwarded Kerberos Requests" nameID="56048" symbol="PerfCounterRODCForward" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.SecuritySystemWide.RODCForward" />
          <counter description="This counter tracks the number of armored Authentication Service (AS) requests that are being processed by the Key Distribution Center (KDC) per second." descriptionID="56054" detailLevel="standard" id="12" name="KDC armored AS Requests" nameID="56052" symbol="PerfCounterFASTAS" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.SecuritySystemWide.FASTAS" />
          <counter description="This counter tracks the number of armored ticket-granting service (TGS) requests that are being processed by the Key Distribution Center (KDC) per second." descriptionID="56058" detailLevel="standard" id="13" name="KDC armored TGS Requests" nameID="56056" symbol="PerfCounterFASTTGS" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.SecuritySystemWide.FASTTGS" />
          <counter description="This counter tracks the number of Authentication Service (AS) requests explicitly requesting claims that are being processed by the Key Distribution Center (KDC) per second." descriptionID="56062" detailLevel="standard" id="14" name="KDC claims-aware AS Requests" nameID="56060" symbol="PerfCounterClaimsAS" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.SecuritySystemWide.ClaimsAS" />
          <counter description="This counter tracks the number of service asserted identity (S4U2Self) TGS requests that are explicitly requesting claims. These requests are being processed by the Key Distribution Center (KDC) per second." descriptionID="56066" detailLevel="standard" id="15" name="KDC claims-aware service asserted identity TGS requests" nameID="56064" symbol="PerfCounterClaimsS4U" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.SecuritySystemWide.ClaimsS4U" />
          <counter description="This counter tracks the number of constrained delegation (S4U2Proxy) TGS requests that are being processed by the Key Distribution Center (KDC) by checking classic type constrained delegation configuration per second. The classic type constrained delegation is restricted to a single domain and configures the backend services SPN on the middle-tier services account object." descriptionID="56070" detailLevel="standard" id="16" name="KDC classic type constrained delegation TGS Requests" nameID="56068" symbol="PerfCounterA2D2" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.SecuritySystemWide.A2D2" />
          <counter description="This counter tracks the number of constrained delegation (S4U2Proxy) TGS requests that are being processed by the Key Distribution Center (KDC) by checking the resource type constrained delegation per second. The resource type constrained delegation can cross domain boundaries and configures the middle-tiers account on the backend services account object." descriptionID="56074" detailLevel="standard" id="17" name="KDC resource type constrained delegation TGS Requests" nameID="56072" symbol="PerfCounterA2DF" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.SecuritySystemWide.A2DF" />
          <counter description="This counter tracks the number of claims-aware ticket-granting service (TGS) requests that are being processed by the Key Distribution Center (KDC) per second. A claims-aware Kerberos client will always request claims during Authentication Service (AS) exchanges." descriptionID="56078" detailLevel="standard" id="18" name="KDC claims-aware TGS Requests" nameID="56076" symbol="PerfCounterClaimsTGS" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.SecuritySystemWide.ClaimsTGS" />
          <counter description="This counter tracks the number of key trust Authentication Service (AS) requests that are being processed by the Key Distribution Center (KDC) per second." descriptionID="56082" detailLevel="standard" id="19" name="KDC key trust AS Requests" nameID="56080" symbol="PerfCounterKeyTrust" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.SecuritySystemWide.KeyTrust" />
        </counterSet>
        <counterSet description="The LSA Lookup performance counter set consists of counters that measure performance of LSA Account name and SID lookups." descriptionID="57002" guid="{4b390836-3626-443d-a6b5-285970bba55b}" instances="single" name="LSA Lookups" nameID="57000" symbol="LsaLookupPerformanceCounterSet" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet">
          <counter description="This counter displays the rate of inbound account name lookup requests from local and network clients to the local LSA." descriptionID="57006" detailLevel="standard" id="1" name="Names Inbound Requests/sec" nameID="57004" symbol="LsaLookupNamesInboundReq" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesInboundReq">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="This counter displays the rate of outbound account name lookup requests from the local LSA to remote servers." descriptionID="57010" detailLevel="standard" id="2" name="Names Outbound Requests/sec" nameID="57008" symbol="LsaLookupNamesOutboundReq" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesOutboundReq">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="This counter displays the rate of incoming isolated name lookup requests to the LSA. " descriptionID="57014" detailLevel="standard" id="3" name="Isolated Names Inbound Requests/sec" nameID="57012" symbol="LsaLookupNamesIsolatedInboundReq" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesIsolatedInboundReq">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="This counter displays the rate of isolated name lookup requests going off box remotely on a Domain Controller." descriptionID="57018" detailLevel="standard" id="4" name="Isolated Names Outbound Requests/sec" nameID="57016" symbol="LsaLookupNamesIsolatedOutboundReq" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesIsolatedOutboundReq">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter baseID="6" description="This counter displays the average completion time of an LsaLookupNames call." descriptionID="57022" detailLevel="standard" id="5" name="Names Completion Time" nameID="57020" symbol="LsaLookupNamesInboundReqTime" type="perf_average_timer" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesInboundReqTime">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="The base value used to calculate the average completion time of an LsaLookupNames call." descriptionID="57026" detailLevel="standard" id="6" name="Names Completion Base" nameID="57024" symbol="LsaLookupNamesInboundReqBase" type="perf_average_base" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesInboundReqBase">
            <counterAttributes>
              <counterAttribute name="noDisplay" />
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter baseID="8" description="This counter displays the time LSA spent waiting on remote server to service a name lookup request." descriptionID="57030" detailLevel="standard" id="7" name="Names Remote Request Time" nameID="57028" symbol="LsaLookupNamesOutboundReqTime" type="perf_average_timer" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesOutboundReqTime">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="The base value used to calculate the average completion time of a remote lookup request." descriptionID="57034" detailLevel="standard" id="8" name="Names Remote Request Base" nameID="57032" symbol="LsaLookupNamesOutboundReqBase" type="perf_average_base" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesOutboundReqBase">
            <counterAttributes>
              <counterAttribute name="noDisplay" />
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="This counter displays the rate of LsaLookupNames call errors per second." descriptionID="57038" detailLevel="standard" id="9" name="Names Errors/sec" nameID="57036" symbol="LsaLookupNamesErrors" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesErrors">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="This counter displays the rate of unresolved names per second." descriptionID="57042" detailLevel="standard" id="10" name="Names Unresolved/sec" nameID="57040" symbol="LsaLookupNamesUnresolved" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesUnresolved">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter baseID="12" description="This counter displays the % name requests resolved from the SID/Name cache." descriptionID="57046" detailLevel="standard" id="11" name="Names Cache % Hit" nameID="57044" symbol="LsaLookupNamesCacheHit" type="perf_sample_fraction" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesCacheHit">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="Invisible base counter for name cache hit counter." descriptionID="57050" detailLevel="standard" id="12" name="Names Cache % Hit Base" nameID="57048" symbol="LsaLookupNamesCacheHitBase" type="perf_sample_base" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesCacheHitBase">
            <counterAttributes>
              <counterAttribute name="noDisplay" />
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter baseID="14" description="This counter displays the % of SID/name cache that is full." descriptionID="57054" detailLevel="standard" id="13" name="Names Cache % Full" nameID="57052" symbol="LsaLookupNamesCacheFull" type="perf_sample_fraction" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesCacheFull">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="Base counter for name cache % full counter." descriptionID="57058" detailLevel="standard" id="14" name="Names Cache % Full Base" nameID="57056" symbol="LsaLookupNamesCacheFullBase" type="perf_sample_base" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesCacheFullBase">
            <counterAttributes>
              <counterAttribute name="noDisplay" />
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="This counter displays the current maximum size of the LSA Name/SID Lookup cache." descriptionID="57062" detailLevel="standard" id="15" name="Name/SID Cache Size(Max Entries)" nameID="57060" symbol="LsaLookupNamesCacheSizeMax" type="perf_counter_rawcount" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesCacheSizeMax">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="This counter displays the rate of LSA Name lookups in trusted forests per second." descriptionID="57066" detailLevel="standard" id="16" name="Names Xforest Requests/sec" nameID="57064" symbol="LsaLookupNamesXforestReq" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesXforestReq">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter baseID="18" description="This counter displays the time LSA spent waiting on a remote server to service a Xforest name lookup request." descriptionID="57070" detailLevel="standard" id="17" name="Names Xforest Time" nameID="57068" symbol="LsaLookupNamesXforestReqTime" type="perf_average_timer" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesXforestReqTime">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="Invisible counter for base value used to calculate the average wait time for completion of a Xforest name lookup request." descriptionID="57074" detailLevel="standard" id="18" name="Names Xforest Base" nameID="57072" symbol="LsaLookupNamesXforestReqBase" type="perf_average_base" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesXforestReqBase">
            <counterAttributes>
              <counterAttribute name="noDisplay" />
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="This counter displays the rate of LSA Name lookups in trusted Domains per second." descriptionID="57078" detailLevel="standard" id="19" name="Names Trusted Domain Requests/sec" nameID="57076" symbol="LsaLookupNamesTrustedDomainReq" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesTrustedDomainReq">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter baseID="21" description="This counter displays the time LSA spent waiting on a remote server in a trusted domain to service a name lookup request." descriptionID="57082" detailLevel="standard" id="20" name="Names Trusted Domain Request Time" nameID="57080" symbol="LsaLookupNamesTrustedDomainReqTime" type="perf_average_timer" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesTrustedDomainReqTime">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="Invisible base counter used to calculate the average wait time for completion of a Trusted Domain lookup request." descriptionID="57086" detailLevel="standard" id="21" name="Names Trusted Domain Request Base" nameID="57084" symbol="LsaLookupNamesTrustedDomainReqBase" type="perf_average_base" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesTrustedDomainReqBase">
            <counterAttributes>
              <counterAttribute name="noDisplay" />
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="This counter displays the rate of remote LSA Name lookups in Primary Domain per second." descriptionID="57090" detailLevel="standard" id="22" name="Names Primary Domain Requests/sec" nameID="57088" symbol="LsaLookupNamesPrimaryDomainReq" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesPrimaryDomainReq">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter baseID="24" description="This counter displays the time LSA spent waiting on a remote server in the primary domain to service a name lookup request." descriptionID="57094" detailLevel="standard" id="23" name="Names Primary Domain Time" nameID="57092" symbol="LsaLookupNamesPrimaryDomainReqTime" type="perf_average_timer" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesPrimaryDomainReqTime">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="Invisible base counter used to calculate the average wait time for completion of a remote name lookup request in Primary Domain." descriptionID="57098" detailLevel="standard" id="24" name="Names Primary Domain Base" nameID="57096" symbol="LsaLookupNamesPrimaryDomainReqBase" type="perf_average_base" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesPrimaryDomainReqBase">
            <counterAttributes>
              <counterAttribute name="noDisplay" />
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="This counter displays the rate of inbound SID lookup requests from local and network clients to the local LSA." descriptionID="57102" detailLevel="standard" id="25" name="SIDs Inbound Requests/sec" nameID="57100" symbol="LsaLookupSidsInboundReq" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupSidsInboundReq">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="This counter displays the rate of outbound SID lookup requests from the local LSA to remote servers." descriptionID="57106" detailLevel="standard" id="26" name="SIDs Outbound Requests/sec" nameID="57104" symbol="LsaLookupSidsOutboundReq" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupSidsOutboundReq">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter baseID="28" description="This counter displays the average completion time of an LsaLookupSids call." descriptionID="57110" detailLevel="standard" id="27" name="SIDs Completion Time" nameID="57108" symbol="LsaLookupSidsInboundReqTime" type="perf_average_timer" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupSidsInboundReqTime">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="Invisible base counter used to calculate the average completion time of an LsaLookupSids call." descriptionID="57114" detailLevel="standard" id="28" name="SIDs Average Completion Time Base" nameID="57112" symbol="LsaLookupSidsInboundReqBase" type="perf_average_base" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupSidsInboundReqBase">
            <counterAttributes>
              <counterAttribute name="noDisplay" />
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter baseID="30" description="This counter displays the time LSA spent waiting on remote server to service a SID lookup request." descriptionID="57118" detailLevel="standard" id="29" name="SIDs Remote Request Time" nameID="57116" symbol="LsaLookupSidsOutboundReqTime" type="perf_average_timer" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupSidsOutboundReqTime">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="Invisible base counter used to calculate the average wait time for completion of a remote SID lookup request." descriptionID="57122" detailLevel="standard" id="30" name="SIDs Remote Request Base" nameID="571120" symbol="LsaLookupSidsOutboundReqBase" type="perf_average_base" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupSidsOutboundReqBase">
            <counterAttributes>
              <counterAttribute name="noDisplay" />
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="This counter displays the rate of LsaLookupSid call errors per second." descriptionID="57126" detailLevel="standard" id="31" name="SIDs Errors/sec" nameID="57124" symbol="LsaLookupSidsErrors" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupSidsErrors">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="This counter displays the rate of unresolved SIDs per second." descriptionID="57130" detailLevel="standard" id="32" name="SIDs Unresolved/sec" nameID="57128" symbol="LsaLookupSidsUnresolved" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupSidsUnresolved">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter baseID="34" description="This counter displays the % SID requests resolved from the cache." descriptionID="57134" detailLevel="standard" id="33" name="SIDs Cache % Hit" nameID="57132" symbol="LsaLookupSidsCacheHit" type="perf_sample_fraction" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupSidsCacheHit">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="Invisible base counter for SID Cache hit counter." descriptionID="57138" detailLevel="standard" id="34" name="SIDs Cache % Hit Base" nameID="57136" symbol="LsaLookupSidsCacheHitBase" type="perf_sample_base" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupSidsCacheHitBase">
            <counterAttributes>
              <counterAttribute name="noDisplay" />
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter baseID="36" description="This counter displays the % of SID cache that is full." descriptionID="57142" detailLevel="standard" id="35" name="SIDs Cache % Full" nameID="57140" symbol="LsaLookupSidsCacheFull" type="perf_sample_fraction" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupSidsCacheFull">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="Invisible base counter for SID cache % full counter." descriptionID="57146" detailLevel="standard" id="36" name="SIDs Cache % Full Base" nameID="57144" symbol="LsaLookupSidsCacheFullBase" type="perf_sample_base" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupSidsCacheFullBase">
            <counterAttributes>
              <counterAttribute name="noDisplay" />
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="This counter displays the rate of SID lookups in trusted forests per second." descriptionID="57150" detailLevel="standard" id="37" name="SIDs Xforest Requests/sec" nameID="57148" symbol="LsaLookupSidsXforestReq" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupSidsXforestReq">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter baseID="39" description="This counter displays the time LSA spent waiting on remote server to service a Xforest SID lookup request." descriptionID="57154" detailLevel="standard" id="38" name="SIDs Xforest Request Time" nameID="57152" symbol="LsaLookupSidsXforestReqTime" type="perf_average_timer" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupSidsXforestReqTime">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="invisible base counter used to calculate the average wait time for completion of a Xforest SID lookup request." descriptionID="57158" detailLevel="standard" id="39" name="SIDs Xforest Request Base" nameID="57156" symbol="LsaLookupSidsXforestReqBase" type="perf_average_base" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupSidsXforestReqBase">
            <counterAttributes>
              <counterAttribute name="noDisplay" />
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="This counter displays the rate of LSA SID lookups for trusted Domains per second." descriptionID="57162" detailLevel="standard" id="40" name="SIDs Trusted Domain Requests/sec" nameID="57160" symbol="LsaLookupSidsTrustedDomainReq" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupSidsTrustedDomainReq">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter baseID="42" description="This counter displays the time LSA spent waiting on remote server in a trusted domain to service a SID lookup request." descriptionID="57166" detailLevel="standard" id="41" name="SIDs Trusted Domain Request Time" nameID="57164" symbol="LsaLookupSidsTrustedDomainReqTime" type="perf_average_timer" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupSidsTrustedDomainReqTime">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="Invisible base counter used to calculate the average wait time for completion of SID lookup request in a Trusted Domain." descriptionID="57170" detailLevel="standard" id="42" name="SIDs Trusted Domain Base" nameID="57168" symbol="LsaLookupSidsTrustedDomainReqBase" type="perf_average_base" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupSidsTrustedDomainReqBase">
            <counterAttributes>
              <counterAttribute name="noDisplay" />
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="This counter displays the rate of remote LSA SID lookups in Primary Domain per second." descriptionID="57174" detailLevel="standard" id="43" name="SIDs Primary Domain Requests/sec" nameID="57172" symbol="LsaLookupSidsPrimaryDomainReq" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupSidsPrimaryDomainReq">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter baseID="45" description="This counter displays the average time it took for a remote server to service a SID lookup request in Primary Domain." descriptionID="57178" detailLevel="standard" id="44" name="SIDs Primary Domain Request Time" nameID="57176" symbol="LsaLookupSidsPrimaryDomainReqTime" type="perf_average_timer" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupSidsPrimaryDomainReqTime">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="Invisible base counter used to calculate the average completion time of a remote SID lookup request in Primary Domain." descriptionID="57182" detailLevel="standard" id="45" name="SIDs Primary Domain Base" nameID="57180" symbol="LsaLookupSidsPrimaryDomainReqBase" type="perf_average_base" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupSidsPrimaryDomainReqBase">
            <counterAttributes>
              <counterAttribute name="noDisplay" />
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="The number of SID/Name entries added to the cache" descriptionID="57186" detailLevel="standard" id="46" name="Name/SID cache entries added/sec" nameID="57184" symbol="LsaLookupNamesCacheEntriesAdded" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesCacheEntriesAdded">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
          <counter description="The number of SID/Name entries purged from the cache" descriptionID="57190" detailLevel="standard" id="47" name="Name/SID cache entries purged/sec" nameID="57188" symbol="LsaLookupNamesCacheEntriesPurged" type="perf_counter_counter" uri="Microsoft.Windows.System.PerfCounters.LsaLookupPerformanceCounterSet.LsaLookupNamesCacheEntriesPurged">
            <counterAttributes>
              <counterAttribute name="reference" />
            </counterAttributes>
          </counter>
        </counterSet>
      </provider>
    </counters>
    <events xmlns="http://schemas.microsoft.com/win/2004/08/events" xmlns:win="http://manifests.microsoft.com/win/2004/08/windows/events">
      <provider guid="{199FE037-2B82-40A9-82AC-E1D46C792B99}" message="$(string.eventProviderName)" messageFileName="%windir%\System32\lsasrv.dll" name="LsaSrv" resourceFileName="%windir%\System32\lsasrv.dll" symbol="S_Microsoft_Windows_LSA">
        <channels>
          <importChannel chid="System" name="System" />
          <channel chid="LsaCorePerformance" enabled="false" isolation="Application" name="Microsoft-Windows-LSA/Performance" type="Analytic" />
          <channel chid="Operational" enabled="false" isolation="System" message="$(string.OperationalChannelName)" name="Microsoft-Windows-LSA/Operational" type="Operational" />
          <channel chid="LsaDiagnostic" enabled="false" isolation="System" message="$(string.DiagnosticChannelName)" name="Microsoft-Windows-LSA/Diagnostic" type="Analytic" />
        </channels>
      </provider>
      <provider guid="{5b004607-1087-4f16-b10e-979685a8d131}" messageFileName="%SystemRoot%\system32\lsasrv.dll" name="Microsoft-Windows-DomainJoinManagerTriggerProvider" resourceFileName="%SystemRoot%\system32\lsasrv.dll" symbol="Symbol_DomainJoinMgrTriggerProvider" />
      <provider guid="{1f678132-5938-4686-9fdc-c8ff68f15c85}" messageFileName="%windir%\System32\lsasrv.dll" name="Schannel" resourceFileName="%windir%\System32\lsasrv.dll" symbol="S_Microsoft_Windows_Schannel">
        <channels>
          <importChannel chid="System" name="System" />
        </channels>
      </provider>
      <provider guid="{dddc1d91-51a1-4a8d-95b5-350c4ee3d809}" message="$(string.eventAuthenticationProviderName)" messageFileName="%windir%\System32\lsasrv.dll" name="Microsoft-Windows-AuthenticationProvider" resourceFileName="%windir%\System32\lsasrv.dll" symbol="S_Microsoft_Windows_AP">
        <channels>
          <channel chid="ProtectedUserClient" enabled="false" isolation="System" message="$(string.ProtectedUserClientChannelName)" name="Microsoft-Windows-Authentication/ProtectedUser-Client" type="Operational" />
          <channel chid="ProtectedUserFailuresDC" enabled="false" isolation="System" message="$(string.ProtectedUserFailuresDCChannelName)" name="Microsoft-Windows-Authentication/ProtectedUserFailures-DomainController" type="Operational" />
          <channel chid="ProtectedUserSuccessesDC" enabled="false" isolation="System" message="$(string.ProtectedUserSuccessesDCChannelName)" name="Microsoft-Windows-Authentication/ProtectedUserSuccesses-DomainController" type="Operational" />
          <channel chid="AuthenticationPolicyFailuresDC" enabled="false" isolation="System" message="$(string.AuthenticationPolicyFailuresDCChannelName)" name="Microsoft-Windows-Authentication/AuthenticationPolicyFailures-DomainController" type="Operational" />
        </channels>
      </provider>
      <messageTable>
        <message message="$(string.event_SPMEVENT_PACKAGE_FAULT)" value="0x1388" />
        <message message="$(string.event_LSA_SECRET_UPGRADE_ERROR)" value="0x178B" />
        <message message="$(string.event_LSA_OPEN_POLICY_BY_ANONYMOUS_REJECTED)" value="0x1791" />
        <message message="$(string.event_LSA_TOO_MANY_CONTEXT_IDS)" value="0x1793" />
        <message message="$(string.event_LSAEVENT_LOOKUP_SC_FAILED)" value="0x8005" />
        <message message="$(string.event_LSAEVENT_LOOKUP_SC_HANDLE_FAILED)" value="0x8006" />
        <message message="$(string.event_LSAEVENT_LOOKUP_SC_LOOKUP_FAILED)" value="0x8007" />
        <message message="$(string.event_LSAEVENT_LOOKUP_TCPIP_NOT_INSTALLED)" value="0x8009" />
        <message message="$(string.event_LSAEVENT_UBPM_NOTIFICATION_FAILED)" value="0x800C" />
        <message message="$(string.event_SSLEVENT_SCHANNEL_STARTED)" value="0x9000" />
        <message message="$(string.event_SSLEVENT_GLOBAL_ACQUIRE_CONTEXT_FAILED)" value="0x9001" />
        <message message="$(string.event_SSLEVENT_CREATE_CRED)" value="0x9003" />
        <message message="$(string.event_SSLEVENT_CRED_PROPERTIES)" value="0x9004" />
        <message message="$(string.event_SSLEVENT_NO_PRIVATE_KEY)" value="0x9005" />
        <message message="$(string.event_SSLEVENT_CRED_ACQUIRE_CONTEXT_FAILED)" value="0x9006" />
        <message message="$(string.event_SSLEVENT_CREATE_CRED_FAILED)" value="0x9007" />
        <message message="$(string.event_SSLEVENT_GET_CERT_CHAIN_FAILURE)" value="0x9008" />
        <message message="$(string.event_SSLEVENT_NO_DEFAULT_SERVER_CRED)" value="0x9016" />
        <message message="$(string.event_SSLEVENT_NO_CIPHERS_SUPPORTED)" value="0x9009" />
        <message message="$(string.event_SSLEVENT_CIPHER_MISMATCH)" value="0x900A" />
        <message message="$(string.event_SSLEVENT_NO_CLIENT_CERT_FOUND)" value="0x900B" />
        <message message="$(string.event_SSLEVENT_BOGUS_SERVER_CERT)" value="0x900C" />
        <message message="$(string.event_SSLEVENT_BOGUS_CLIENT_CERT)" value="0x900D" />
        <message message="$(string.event_SSLEVENT_FAST_MAPPING_FAILURE)" value="0x900E" />
        <message message="$(string.event_SSLEVENT_CERT_MAPPING_FAILURE)" value="0x900F" />
        <message message="$(string.event_SSLEVENT_HANDSHAKE_INFO)" value="0x9010" />
        <message message="$(string.event_SSLEVENT_EXPIRED_SERVER_CERT)" value="0x9011" />
        <message message="$(string.event_SSLEVENT_UNTRUSTED_SERVER_CERT)" value="0x9012" />
        <message message="$(string.event_SSLEVENT_REVOKED_SERVER_CERT)" value="0x9013" />
        <message message="$(string.event_SSLEVENT_NAME_MISMATCHED_SERVER_CERT)" value="0x9014" />
        <message message="$(string.event_SSLEVENT_ISSUER_LIST_OVERFLOW_FAILURE)" value="0x9015" />
        <message message="$(string.event_SSLEVENT_RECEIVE_FATAL_ALERT)" value="0x9017" />
        <message message="$(string.event_SSLEVENT_GENERATE_FATAL_ALERT)" value="0x9018" />
        <message message="$(string.event_SSLEVENT_INCOMPLETE_CERT_CHAIN_FAILURE)" value="0x9019" />
        <message message="$(string.event_SSLEVENT_OCSP_STATUS_RETRIEVAL_FAILURE)" value="0x9040" />
        <message message="$(string.event_NEGOTIATE_DOWNGRADE_DETECTED)" value="0xA000" />
        <message message="$(string.event_NEGOTIATE_INVALID_SERVER)" value="0xA001" />
        <message message="$(string.event_NEGOTIATE_UNBALANCED_EXCHANGE)" value="0xA002" />
        <message message="$(string.event_NEGOTIATE_UNKNOWN_PACKAGE)" value="0xA004" />
        <message message="$(string.event_NEGOTIATE_PACKAGE_SELECTED)" value="0xA005" />
        <message message="$(string.event_NEGOTIATE_MESSAGE_DECODED)" value="0xA006" />
        <message message="$(string.event_NEGOTIATE_RAW_PACKET)" value="0xA007" />
        <message message="$(string.event_NEGOTIATE_UNKNOWN_PACKET)" value="0xA008" />
        <message message="$(string.event_NEGOTIATE_MESSAGE_DECODED_NO_TOKEN)" value="0xA009" />
        <message message="$(string.event_LOGON_CACHE_DISABLED_MSG)" value="0xB000" />
        <message message="$(string.event_LOGON_ENTRY_DELETED_MSG)" value="0xB001" />
        <message message="$(string.event_LOGON_ENTRY_FLUSHED_MSG)" value="0xB002" />
        <message message="$(string.event_LSA_INVALID_TARGET_INFO)" value="0x1798" />
        <message message="$(string.event_LSA_NTLM_USAGE_INFO)" value="0x1797" />
        <message message="$(string.event_LSA_NTLM_USAGE)" value="0x1796" />
        <message message="$(string.event_LSA_LOOPBACK_REJECTED)" value="0x1795" />
        <message message="$(string.event_LSA_NO_TARGET_NAME)" value="0x1794" />
        <message message="$(string.event_LSA_ENCRYPTED_SECRET_RETURNED)" value="0x1800" />
        <message message="$(string.event_LSA_CENTRAL_ACCESS_POLICIES_MISSING)" value="0x1801" />
        <message message="$(string.event_LSA_BAD_CENTRAL_ACCESS_RULE)" value="0x1802" />
        <message message="$(string.event_LSA_CREDENTIAL_GUARD_NOT_LICENSED)" value="0x1803" />
        <message message="$(string.event_LSA_CREDENTIAL_GUARD_CREDMAN_AUDIT)" value="0x180A" />
        <message message="$(string.event_LSA_CREDENTIAL_GUARD_PACKAGE_AUDIT)" value="0x180B" />
        <message message="$(string.event_LSA_CREDENTIAL_GUARD_AUTO_ENABLEMENT)" value="0x180C" />
        <message message="$(string.event_LSA_LSAISO_UEFI_READ_ERROR)" value="0x180E" />
        <message message="$(string.event_LSA_LSAISO_LAUNCH_FAILURE)" value="0x1810" />
        <message message="$(string.event_LSA_LSAISO_CONFIG)" value="0x1811" />
        <message message="$(string.event_LSA_LSAISO_KEYGUARD)" value="0x1812" />
        <message message="$(string.event_LSA_LSAISO_CREDGUARD)" value="0x1813" />
        <message message="$(string.event_LSA_LSAISO_SK_NOT_PRESENT)" value="0x1814" />
        <message message="$(string.event_LSA_LSAISO_MACHINE_IDENTITY_ISOLATION_FALLBACK)" value="0x1815" />
        <message message="$(string.event_LSA_MACHINE_CREDENTIAL_STATUS)" value="0x1816" />
        <message message="$(string.event_LSA_MACHINE_ID_PARTIAL_MISMATCH)" value="0x1817" />
        <message message="$(string.event_LSA_ALLOW_UAC_BYPASS)" value="0x1818" />
        <message message="$(string.event_LSA_GROUPS_AT_LOGON)" value="0x012C" />
        <message message="$(string.event_LSA_CLAIMS_AT_LOGON)" value="0x012D" />
        <message message="$(string.event_LSA_PACKAGE_NO_CREDENTIAL)" value="0x64" />
        <message message="$(string.event_LSA_PACKAGE_POST_LOGOFF_REQUEST)" value="0xC8" />
        <message message="$(string.event_LSA_USER_LOGOFF_NOTIFICATION)" value="0x12E" />
        <message message="$(string.event_LSA_PACKAGE_NOT_CACHE_LOGON_USER)" value="0x12F" />
        <message message="$(string.event_LSA_CONFIGURE_AUTOLOGON_CREDENTIALS_SUCCESS)" value="0x0140" />
        <message message="$(string.event_LSA_CONFIGURE_AUTOLOGON_CREDENTIALS_FAILURE)" value="0x0141" />
        <message message="$(string.event_LSA_DELETE_AUTOLOGON_CREDENTIALS)" value="0x0142" />
        <message message="$(string.msg_LSAP_UNUSED_MESSAGE)" mid="LSAP_UNUSED_MESSAGE" symbol="LSAP_UNUSED_MESSAGE" value="0x00001FFF" />
        <message message="$(string.msg_LSAP_SID_NAME_NULL)" mid="LSAP_SID_NAME_NULL" symbol="LSAP_SID_NAME_NULL" value="0x00002000" />
        <message message="$(string.msg_LSAP_SID_NAME_WORLD)" mid="LSAP_SID_NAME_WORLD" symbol="LSAP_SID_NAME_WORLD" value="0x00002001" />
        <message message="$(string.msg_LSAP_SID_NAME_LOCAL)" mid="LSAP_SID_NAME_LOCAL" symbol="LSAP_SID_NAME_LOCAL" value="0x00002002" />
        <message message="$(string.msg_LSAP_SID_NAME_CREATOR_OWNER)" mid="LSAP_SID_NAME_CREATOR_OWNER" symbol="LSAP_SID_NAME_CREATOR_OWNER" value="0x00002003" />
        <message message="$(string.msg_LSAP_SID_NAME_CREATOR_GROUP)" mid="LSAP_SID_NAME_CREATOR_GROUP" symbol="LSAP_SID_NAME_CREATOR_GROUP" value="0x00002004" />
        <message message="$(string.msg_LSAP_SID_NAME_NT_DOMAIN)" mid="LSAP_SID_NAME_NT_DOMAIN" symbol="LSAP_SID_NAME_NT_DOMAIN" value="0x00002005" />
        <message message="$(string.msg_LSAP_SID_NAME_NT_AUTHORITY)" mid="LSAP_SID_NAME_NT_AUTHORITY" symbol="LSAP_SID_NAME_NT_AUTHORITY" value="0x00002006" />
        <message message="$(string.msg_LSAP_SID_NAME_DIALUP)" mid="LSAP_SID_NAME_DIALUP" symbol="LSAP_SID_NAME_DIALUP" value="0x00002007" />
        <message message="$(string.msg_LSAP_SID_NAME_NETWORK)" mid="LSAP_SID_NAME_NETWORK" symbol="LSAP_SID_NAME_NETWORK" value="0x00002008" />
        <message message="$(string.msg_LSAP_SID_NAME_BATCH)" mid="LSAP_SID_NAME_BATCH" symbol="LSAP_SID_NAME_BATCH" value="0x00002009" />
        <message message="$(string.msg_LSAP_SID_NAME_INTERACTIVE)" mid="LSAP_SID_NAME_INTERACTIVE" symbol="LSAP_SID_NAME_INTERACTIVE" value="0x0000200A" />
        <message message="$(string.msg_LSAP_SID_NAME_SERVICE)" mid="LSAP_SID_NAME_SERVICE" symbol="LSAP_SID_NAME_SERVICE" value="0x0000200B" />
        <message message="$(string.msg_LSAP_SID_NAME_BUILTIN)" mid="LSAP_SID_NAME_BUILTIN" symbol="LSAP_SID_NAME_BUILTIN" value="0x0000200C" />
        <message message="$(string.msg_LSAP_SID_NAME_SYSTEM)" mid="LSAP_SID_NAME_SYSTEM" symbol="LSAP_SID_NAME_SYSTEM" value="0x0000200D" />
        <message message="$(string.msg_LSAP_SID_NAME_ANONYMOUS)" mid="LSAP_SID_NAME_ANONYMOUS" symbol="LSAP_SID_NAME_ANONYMOUS" value="0x0000200E" />
        <message message="$(string.msg_LSAP_SID_NAME_CREATOR_OWNER_SERVER)" mid="LSAP_SID_NAME_CREATOR_OWNER_SERVER" symbol="LSAP_SID_NAME_CREATOR_OWNER_SERVER" value="0x0000200F" />
        <message message="$(string.msg_LSAP_SID_NAME_CREATOR_GROUP_SERVER)" mid="LSAP_SID_NAME_CREATOR_GROUP_SERVER" symbol="LSAP_SID_NAME_CREATOR_GROUP_SERVER" value="0x00002010" />
        <message message="$(string.msg_LSAP_SID_NAME_SERVER)" mid="LSAP_SID_NAME_SERVER" symbol="LSAP_SID_NAME_SERVER" value="0x00002011" />
        <message message="$(string.msg_LSAP_SID_NAME_SELF)" mid="LSAP_SID_NAME_SELF" symbol="LSAP_SID_NAME_SELF" value="0x00002012" />
        <message message="$(string.msg_LSAP_SID_NAME_AUTHENTICATED_USER)" mid="LSAP_SID_NAME_AUTHENTICATED_USER" symbol="LSAP_SID_NAME_AUTHENTICATED_USER" value="0x00002013" />
        <message message="$(string.msg_LSAP_SID_NAME_RESTRICTED)" mid="LSAP_SID_NAME_RESTRICTED" symbol="LSAP_SID_NAME_RESTRICTED" value="0x00002014" />
        <message message="$(string.msg_LSAP_SID_NAME_INTERNET)" mid="LSAP_SID_NAME_INTERNET" symbol="LSAP_SID_NAME_INTERNET" value="0x00002015" />
        <message message="$(string.msg_LSAP_SID_NAME_TERMINAL_SERVER)" mid="LSAP_SID_NAME_TERMINAL_SERVER" symbol="LSAP_SID_NAME_TERMINAL_SERVER" value="0x00002016" />
        <message message="$(string.msg_LSAP_SID_NAME_PROXY)" mid="LSAP_SID_NAME_PROXY" symbol="LSAP_SID_NAME_PROXY" value="0x00002017" />
        <message message="$(string.msg_LSAP_SID_NAME_LOCALSERVICE)" mid="LSAP_SID_NAME_LOCALSERVICE" symbol="LSAP_SID_NAME_LOCALSERVICE" value="0x00002018" />
        <message message="$(string.msg_LSAP_SID_NAME_NETWORKSERVICE)" mid="LSAP_SID_NAME_NETWORKSERVICE" symbol="LSAP_SID_NAME_NETWORKSERVICE" value="0x00002019" />
        <message message="$(string.msg_LSAP_SID_NAME_REMOTE_INTERACTIVE)" mid="LSAP_SID_NAME_REMOTE_INTERACTIVE" symbol="LSAP_SID_NAME_REMOTE_INTERACTIVE" value="0x0000201A" />
        <message message="$(string.msg_LSAP_SID_NAME_USERS)" mid="LSAP_SID_NAME_USERS" symbol="LSAP_SID_NAME_USERS" value="0x0000201B" />
        <message message="$(string.msg_LSAP_SID_NAME_NTLM_AUTH)" mid="LSAP_SID_NAME_NTLM_AUTH" symbol="LSAP_SID_NAME_NTLM_AUTH" value="0x0000201C" />
        <message message="$(string.msg_LSAP_SID_NAME_DIGEST_AUTH)" mid="LSAP_SID_NAME_DIGEST_AUTH" symbol="LSAP_SID_NAME_DIGEST_AUTH" value="0x0000201D" />
        <message message="$(string.msg_LSAP_SID_NAME_SCHANNEL_AUTH)" mid="LSAP_SID_NAME_SCHANNEL_AUTH" symbol="LSAP_SID_NAME_SCHANNEL_AUTH" value="0x0000201E" />
        <message message="$(string.msg_LSAP_SID_NAME_THIS_ORGANIZATION)" mid="LSAP_SID_NAME_THIS_ORGANIZATION" symbol="LSAP_SID_NAME_THIS_ORGANIZATION" value="0x0000201F" />
        <message message="$(string.msg_LSAP_SID_NAME_OTHER_ORGANIZATION)" mid="LSAP_SID_NAME_OTHER_ORGANIZATION" symbol="LSAP_SID_NAME_OTHER_ORGANIZATION" value="0x00002020" />
        <message message="$(string.msg_LSAP_SID_NAME_IUSER)" mid="LSAP_SID_NAME_IUSER" symbol="LSAP_SID_NAME_IUSER" value="0x00002021" />
        <message message="$(string.msg_LSAP_SID_NAME_MANDATORY_LABEL_AUTHORITY)" mid="LSAP_SID_NAME_MANDATORY_LABEL_AUTHORITY" symbol="LSAP_SID_NAME_MANDATORY_LABEL_AUTHORITY" value="0x00002022" />
        <message message="$(string.msg_LSAP_SID_NAME_MANDATORY_LABEL_UNTRUSTED)" mid="LSAP_SID_NAME_MANDATORY_LABEL_UNTRUSTED" symbol="LSAP_SID_NAME_MANDATORY_LABEL_UNTRUSTED" value="0x00002023" />
        <message message="$(string.msg_LSAP_SID_NAME_MANDATORY_LABEL_LOW)" mid="LSAP_SID_NAME_MANDATORY_LABEL_LOW" symbol="LSAP_SID_NAME_MANDATORY_LABEL_LOW" value="0x00002024" />
        <message message="$(string.msg_LSAP_SID_NAME_MANDATORY_LABEL_MEDIUM)" mid="LSAP_SID_NAME_MANDATORY_LABEL_MEDIUM" symbol="LSAP_SID_NAME_MANDATORY_LABEL_MEDIUM" value="0x00002025" />
        <message message="$(string.msg_LSAP_SID_NAME_MANDATORY_LABEL_HIGH)" mid="LSAP_SID_NAME_MANDATORY_LABEL_HIGH" symbol="LSAP_SID_NAME_MANDATORY_LABEL_HIGH" value="0x00002026" />
        <message message="$(string.msg_LSAP_SID_NAME_MANDATORY_LABEL_SYSTEM)" mid="LSAP_SID_NAME_MANDATORY_LABEL_SYSTEM" symbol="LSAP_SID_NAME_MANDATORY_LABEL_SYSTEM" value="0x00002027" />
        <message message="$(string.msg_LSAP_SID_NAME_MANDATORY_LABEL_PROTECTED_PROCESS)" mid="LSAP_SID_NAME_MANDATORY_LABEL_PROTECTED_PROCESS" symbol="LSAP_SID_NAME_MANDATORY_LABEL_PROTECTED_PROCESS" value="0x0000202A" />
        <message message="$(string.msg_LSAP_SID_NAME_CREATOR_OWNER_RIGHTS)" mid="LSAP_SID_NAME_CREATOR_OWNER_RIGHTS" symbol="LSAP_SID_NAME_CREATOR_OWNER_RIGHTS" value="0x0000202B" />
        <message message="$(string.msg_LSAP_SID_NAME_WRITE_RESTRICTED)" mid="LSAP_SID_NAME_WRITE_RESTRICTED" symbol="LSAP_SID_NAME_WRITE_RESTRICTED" value="0x0000202C" />
        <message message="$(string.msg_LSAP_SID_NAME_ERODC)" mid="LSAP_SID_NAME_ERODC" symbol="LSAP_SID_NAME_ERODC" value="0x0000202D" />
        <message message="$(string.msg_LSAP_SID_NAME_MANDATORY_LABEL_MEDIUM_PLUS)" mid="LSAP_SID_NAME_MANDATORY_LABEL_MEDIUM_PLUS" symbol="LSAP_SID_NAME_MANDATORY_LABEL_MEDIUM_PLUS" value="0x0000202E" />
        <message message="$(string.msg_LSAP_SID_NAME_LOCAL_LOGON)" mid="LSAP_SID_NAME_LOCAL_LOGON" symbol="LSAP_SID_NAME_LOCAL_LOGON" value="0x0000202F" />
        <message message="$(string.msg_LSAP_SID_NAME_THIS_ORG_CERT)" mid="LSAP_SID_NAME_THIS_ORG_CERT" symbol="LSAP_SID_NAME_THIS_ORG_CERT" value="0x00002030" />
        <message message="$(string.msg_LSAP_SID_NAME_ALL_APP_PACKAGES)" mid="LSAP_SID_NAME_ALL_APP_PACKAGES" symbol="LSAP_SID_NAME_ALL_APP_PACKAGES" value="0x00002031" />
        <message message="$(string.msg_LSAP_SID_NAME_APP_PACKAGE_AUTHORITY)" mid="LSAP_SID_NAME_APP_PACKAGE_AUTHORITY" symbol="LSAP_SID_NAME_APP_PACKAGE_AUTHORITY" value="0x00002032" />
        <message message="$(string.msg_LSAP_SID_NAME_CAPABILITY_INTERNET_CLIENT)" mid="LSAP_SID_NAME_CAPABILITY_INTERNET_CLIENT" symbol="LSAP_SID_NAME_CAPABILITY_INTERNET_CLIENT" value="0x00002033" />
        <message message="$(string.msg_LSAP_SID_NAME_CAPABILITY_INTERNET_CLIENT_SERVER)" mid="LSAP_SID_NAME_CAPABILITY_INTERNET_CLIENT_SERVER" symbol="LSAP_SID_NAME_CAPABILITY_INTERNET_CLIENT_SERVER" value="0x00002034" />
        <message message="$(string.msg_LSAP_SID_NAME_CAPABILITY_PRIVATE_NETWORK_CLIENT_SERVER)" mid="LSAP_SID_NAME_CAPABILITY_PRIVATE_NETWORK_CLIENT_SERVER" symbol="LSAP_SID_NAME_CAPABILITY_PRIVATE_NETWORK_CLIENT_SERVER" value="0x00002035" />
        <message message="$(string.msg_LSAP_SID_NAME_CAPABILITY_PICTURES_LIBRARY)" mid="LSAP_SID_NAME_CAPABILITY_PICTURES_LIBRARY" symbol="LSAP_SID_NAME_CAPABILITY_PICTURES_LIBRARY" value="0x00002036" />
        <message message="$(string.msg_LSAP_SID_NAME_CAPABILITY_VIDEOS_LIBRARY)" mid="LSAP_SID_NAME_CAPABILITY_VIDEOS_LIBRARY" symbol="LSAP_SID_NAME_CAPABILITY_VIDEOS_LIBRARY" value="0x00002037" />
        <message message="$(string.msg_LSAP_SID_NAME_CAPABILITY_MUSIC_LIBRARY)" mid="LSAP_SID_NAME_CAPABILITY_MUSIC_LIBRARY" symbol="LSAP_SID_NAME_CAPABILITY_MUSIC_LIBRARY" value="0x00002038" />
        <message message="$(string.msg_LSAP_SID_NAME_CAPABILITY_DOCUMENTS_LIBRARY)" mid="LSAP_SID_NAME_CAPABILITY_DOCUMENTS_LIBRARY" symbol="LSAP_SID_NAME_CAPABILITY_DOCUMENTS_LIBRARY" value="0x00002039" />
        <message message="$(string.msg_LSAP_SID_NAME_CAPABILITY_ENTERPRISE_AUTHENTICATION)" mid="LSAP_SID_NAME_CAPABILITY_ENTERPRISE_AUTHENTICATION" symbol="LSAP_SID_NAME_CAPABILITY_ENTERPRISE_AUTHENTICATION" value="0x0000203B" />
        <message message="$(string.msg_LSAP_SID_NAME_CAPABILITY_SHARED_USER_CERTIFICATES)" mid="LSAP_SID_NAME_CAPABILITY_SHARED_USER_CERTIFICATES" symbol="LSAP_SID_NAME_CAPABILITY_SHARED_USER_CERTIFICATES" value="0x0000203C" />
        <message message="$(string.msg_LSAP_SID_NAME_CAPABILITY_REMOVABLE_STORAGE)" mid="LSAP_SID_NAME_CAPABILITY_REMOVABLE_STORAGE" symbol="LSAP_SID_NAME_CAPABILITY_REMOVABLE_STORAGE" value="0x0000203D" />
        <message message="$(string.msg_LSAP_SID_NAME_USER_MODE_DRIVERS)" mid="LSAP_SID_NAME_USER_MODE_DRIVERS" symbol="LSAP_SID_NAME_USER_MODE_DRIVERS" value="0x0000203E" />
        <message message="$(string.msg_LSAP_SID_NAME_SENTINEL_CLAIMS)" mid="LSAP_SID_NAME_SENTINEL_CLAIMS" symbol="LSAP_SID_NAME_SENTINEL_CLAIMS" value="0x0000203F" />
        <message message="$(string.msg_LSAP_SID_NAME_SENTINEL_COMPOUND)" mid="LSAP_SID_NAME_SENTINEL_COMPOUND" symbol="LSAP_SID_NAME_SENTINEL_COMPOUND" value="0x00002040" />
        <message message="$(string.msg_LSAP_DEFAULT_DOMAIN_NAME)" mid="LSAP_DEFAULT_DOMAIN_NAME" symbol="LSAP_DEFAULT_DOMAIN_NAME" value="0x00004000" />
        <message message="$(string.msg_SSLEVENTTEXT_CLIENT)" mid="SSLEVENTTEXT_CLIENT" symbol="SSLEVENTTEXT_CLIENT" value="0x80009080" />
        <message message="$(string.msg_SSLEVENTTEXT_SERVER)" mid="SSLEVENTTEXT_SERVER" symbol="SSLEVENTTEXT_SERVER" value="0x80009081" />
        <message message="$(string.msg_CRED_TEXT_ENTERPRISECRED_DATA)" mid="CRED_TEXT_ENTERPRISECRED_DATA" symbol="CRED_TEXT_ENTERPRISECRED_DATA" value="0x8000C000" />
        <message message="$(string.msg_CRED_TEXT_LOCALCRED_DATA)" mid="CRED_TEXT_LOCALCRED_DATA" symbol="CRED_TEXT_LOCALCRED_DATA" value="0x8000C001" />
        <message message="$(string.msg_LSAP_SID_NAME_LIVESSP_AUTH)" mid="LSAP_SID_NAME_LIVESSP_AUTH" symbol="LSAP_SID_NAME_LIVESSP_AUTH" value="0x00002041" />
        <message message="$(string.msg_LSAP_SID_NAME_AUTHENTICATION_AUTHORITY_ASSERTED)" mid="LSAP_SID_NAME_AUTHENTICATION_AUTHORITY_ASSERTED" symbol="LSAP_SID_NAME_AUTHENTICATION_AUTHORITY_ASSERTED" value="0x00002042" />
        <message message="$(string.msg_LSAP_SID_NAME_AUTHENTICATION_SERVICE_ASSERTED)" mid="LSAP_SID_NAME_AUTHENTICATION_SERVICE_ASSERTED" symbol="LSAP_SID_NAME_AUTHENTICATION_SERVICE_ASSERTED" value="0x00002043" />
        <message message="$(string.msg_LSAP_SID_NAME_LOCAL_ACCOUNT)" mid="LSAP_SID_NAME_LOCAL_ACCOUNT" symbol="LSAP_SID_NAME_LOCAL_ACCOUNT" value="0x00002044" />
        <message message="$(string.msg_LSAP_SID_NAME_LOCAL_ACCOUNT_AND_ADMINISTRATOR)" mid="LSAP_SID_NAME_LOCAL_ACCOUNT_AND_ADMINISTRATOR" symbol="LSAP_SID_NAME_LOCAL_ACCOUNT_AND_ADMINISTRATOR" value="0x00002045" />
        <message message="$(string.msg_LSAP_SID_NAME_CAPABILITY_APPOINTMENTS)" mid="LSAP_SID_NAME_CAPABILITY_APPOINTMENTS" symbol="LSAP_SID_NAME_CAPABILITY_APPOINTMENTS" value="0x00002046" />
        <message message="$(string.msg_LSAP_SID_NAME_CAPABILITY_CONTACTS)" mid="LSAP_SID_NAME_CAPABILITY_CONTACTS" symbol="LSAP_SID_NAME_CAPABILITY_CONTACTS" value="0x00002047" />
        <message message="$(string.msg_LSAP_SID_NAME_DEFAULT_ACCOUNT)" mid="LSAP_SID_NAME_DEFAULT_ACCOUNT" symbol="LSAP_SID_NAME_DEFAULT_ACCOUNT" value="0x00002048" />
        <message message="$(string.msg_LSAP_SID_NAME_DEFAULT_ACCOUNT_GROUP)" mid="LSAP_SID_NAME_DEFAULT_ACCOUNT_GROUP" symbol="LSAP_SID_NAME_DEFAULT_ACCOUNT_GROUP" value="0x00002049" />
        <message message="$(string.msg_LSAP_SID_NAME_CLOUDAP_AUTH)" mid="LSAP_SID_NAME_CLOUDAP_AUTH" symbol="LSAP_SID_NAME_CLOUDAP_AUTH" value="0x0000204A" />
        <message message="$(string.msg_LSAP_SID_NAME_AUTHENTICATION_KEY_TRUST)" mid="LSAP_SID_NAME_AUTHENTICATION_KEY_TRUST" symbol="LSAP_SID_NAME_AUTHENTICATION_KEY_TRUST" value="0x0000204B" />
        <message message="$(string.msg_LSAP_SID_NAME_AUTHENTICATION_KEY_PROPERTY_MFA)" mid="LSAP_SID_NAME_AUTHENTICATION_KEY_PROPERTY_MFA" symbol="LSAP_SID_NAME_AUTHENTICATION_KEY_PROPERTY_MFA" value="0x0000204C" />
        <message message="$(string.msg_LSAP_SID_NAME_AUTHENTICATION_KEY_PROPERTY_ATTESTATION)" mid="LSAP_SID_NAME_AUTHENTICATION_KEY_PROPERTY_ATTESTATION" symbol="LSAP_SID_NAME_AUTHENTICATION_KEY_PROPERTY_ATTESTATION" value="0x0000204D" />
        <message message="$(string.msg_LSAP_SID_NAME_AUTHENTICATION_FRESHNESS)" mid="LSAP_SID_NAME_AUTHENTICATION_FRESHNESS" symbol="LSAP_SID_NAME_AUTHENTICATION_FRESHNESS" value="0x0000204E" />
        <message message="$(string.msg_LSAP_SID_NAME_ALL_RESTRICTED_APP_PACKAGES)" mid="LSAP_SID_NAME_ALL_RESTRICTED_APP_PACKAGES" symbol="LSAP_SID_NAME_ALL_RESTRICTED_APP_PACKAGES" value="0x0000204F" />
        <message message="$(string.msg_LSAP_SID_NAME_WINDOW_MANAGER_GROUP)" mid="LSAP_SID_NAME_WINDOW_MANAGER_GROUP" symbol="LSAP_SID_NAME_WINDOW_MANAGER_GROUP" value="0x00002050" />
        <message message="$(string.msg_LSAP_SID_NAME_DEVICE_OWNERS_GROUP)" mid="LSAP_SID_NAME_DEVICE_OWNERS_GROUP" symbol="LSAP_SID_NAME_DEVICE_OWNERS_GROUP" value="0x00002051" />
        <message message="$(string.msg_LSAP_SID_NAME_RESTRICTED_SERVICES)" mid="LSAP_SID_NAME_RESTRICTED_SERVICES" symbol="LSAP_SID_NAME_RESTRICTED_SERVICES" value="0x00002052" />
        <message message="$(string.msg_LSAP_SID_NAME_ALL_RESTRICTED_SERVICES)" mid="LSAP_SID_NAME_ALL_RESTRICTED_SERVICES" symbol="LSAP_SID_NAME_ALL_RESTRICTED_SERVICES" value="0x00002053" />
      </messageTable>
      <cmi />
    </events>
  </instrumentation>
  <localization>
    <resources culture="en-US">
      <stringTable>
        <string id="description" value="Local Security Authority Subsystem" />
        <string id="displayName" value="Local Security Authority Subsystem" />
        <string id="eventProviderName" value="Microsoft-Windows-LSA" />
        <string id="OperationalChannelName" value="Operational" />
        <string id="DiagnosticChannelName" value="Diagnostic" />
        <string id="eventAuthenticationProviderName" value="Microsoft-Windows-Authentication" />
        <string id="ProtectedUserClientChannelName" value="Microsoft-Windows-Authentication/ProtectedUser-Client" />
        <string id="ProtectedUserFailuresDCChannelName" value="Microsoft-Windows-Authentication/ProtectedUserFailures-DomainController" />
        <string id="ProtectedUserSuccessesDCChannelName" value="Microsoft-Windows-Authentication/ProtectedUserSuccesses-DomainController" />
        <string id="AuthenticationPolicyFailuresDCChannelName" value="Microsoft-Windows-Authentication/AuthenticationPolicyFailures-DomainController" />
        <string id="fileSddlDisplayName" value="WRP_FILE_DEFAULT_SDDL" />
        <string id="fileSddlDescription" value="Default SDDL for Windows Resource Protected file" />
        <string id="regSddlDisplayName" value="WRP_REGKEY_DEFAULT_SDDL" />
        <string id="regSddlDescription" value="Default SDDL for Windows Resource Protected registry key" />
        <string id="config_LsaLookupCacheRefreshTime_displayName" value="LSA lookup cache refresh time (in minutes)" />
        <string id="config_LsaLookupCacheRefreshTime_description" value="Contains the time (in minutes) when each entry of the LSA lookup cache needs refreshing" />
        <string id="config_LsaLookupCacheExpireTime_displayName" value="Lsa lookup cache expire time (in minutes)" />
        <string id="config_LsaLookupCacheExpireTime_description" value="Contains the time (in minutes) when each entry of the LSA lookup cache expires" />
        <string id="config_LsaLookupCacheMaxSize_displayName" value="Lsa lookup cache max size" />
        <string id="config_LsaLookupCacheMaxSize_description" value="Contains the maximum number of entries LSA lookup cache" />
        <string id="config_LookupLogLevel_displayName" value="LSA lookup log level" />
        <string id="config_LookupLogLevel_description" value="Contains the setting for LSA lookup log level" />
        <string id="config_LsaLookupReturnSidTypeDeleted_displayName" value="Return sid type deleted for unknown accounts for requests from NT4 clients" />
        <string id="config_LsaLookupReturnSidTypeDeleted_description" value="Contains the setting for allowing NT4 clients to receieve SidTypeDeleted instead of SidTypeUnknown if the domain of the account can be found, but the account cannot be found during sid lookups" />
        <string id="config_LsaLookupRestrictIsolatedNameLevel_displayName" value="Do not allow chaining of lookup requests to external trusted domains if isolated names are used" />
        <string id="config_LsaLookupRestrictIsolatedNameLevel_description" value="Contains the setting for allowing chaining of lookup requests to external trusted domains if isolated names are used" />
        <string id="config_LspDbgInfoLevel_displayName" value="Logging level for LSA Policy operations" />
        <string id="config_LspDbgInfoLevel_description" value="Contains the setting of logging level for LSA Policy operations" />
        <string id="config_LspDbgTraceOptions_displayName" value="Logging options for LSA Policy operations" />
        <string id="config_LspDbgTraceOptions_description" value="Contains the setting of logging options for LSA Policy operations" />
        <string id="task_CATEGORY_SPM" value="Security Package Manager" />
        <string id="task_CATEGORY_LOCATOR" value="Locator" />
        <string id="task_CATEGORY_NEGOTIATE" value="SPNEGO (Negotiator)" />
        <string id="task_CATEGORY_LOGON_CACHE" value="Logon Cache" />
        <string id="task_CATEGORY_LSA_LOGON" value="LSA Logon" />
        <string id="task_CATEGORY_LSA_LOOKUP" value="LSA SID-Name Lookup" />
        <string id="task_CATEGORY_MAX_CATEGORY" value="Max" />
        <string id="event_SPMEVENT_PACKAGE_FAULT" value="The security package %1 generated an exception. The exception information is the data." />
        <string id="event_LSA_SECRET_UPGRADE_ERROR" value="Could not upgrade the global secret %1. Please check the status of all services in the system." />
        <string id="event_LSA_OPEN_POLICY_BY_ANONYMOUS_REJECTED" value="An anonymous session connected from %1 has attempted to open an LSA policy handle on this machine. The attempt was rejected with STATUS_ACCESS_DENIED to prevent leaking security sensitive information to the anonymous caller.%n The application that made this attempt needs to be fixed. Please contact the application vendor. As a temporary workaround, this security measure can be disabled by setting the \HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\TurnOffAnonymousBlock DWORD value to 1.%n This message will be logged at most once a day." />
        <string id="event_LSA_TOO_MANY_CONTEXT_IDS" value="During a logon attempt, the user's security context accumulated too many security IDs. This is a very unusual situation. Remove the user from some global or local groups to reduce the number of security IDs to incorporate into the security context.%nUser's SID is %1%nIf this is the Administrator account, logging on in safe mode will enable Administrator to log on by automatically restricting group memberships." />
        <string id="event_LSAEVENT_LOOKUP_SC_FAILED" value="A lookup request was made that required connectivity to a domain controller in domain %1. The LSA was unable to find a domain controller in the domain and thus failed the request. Please check connectivity and secure channel setup from this domain controller to the domain %2." />
        <string id="event_LSAEVENT_LOOKUP_SC_HANDLE_FAILED" value="A lookup request was made that required connectivity to the domain controller %1. The local LSA was unable to contact the LSA on the remote domain controller. Please check connectivity and secure channel setup from this domain controller to the domain controller %2." />
        <string id="event_LSAEVENT_LOOKUP_SC_LOOKUP_FAILED" value="A lookup request was made that required the lookup services on the remote domain controller %1. The remote domain controller failed the request thus the local LSA failed the original lookup request. Please check connectivity and secure channel setup from this domain controller to the domain controller %2." />
        <string id="event_LSAEVENT_LOOKUP_TCPIP_NOT_INSTALLED" value="The LSA was unable to register its RPC interface over the TCP/IP interface. Please make sure that the protocol is properly installed." />
        <string id="event_LSAEVENT_UBPM_NOTIFICATION_FAILED" value="The LSA was unable to notify UBPM during startup with status %1." />
        <string id="event_SSLEVENT_SCHANNEL_STARTED" value="The schannel security package has loaded successfully." />
        <string id="event_SSLEVENT_GLOBAL_ACQUIRE_CONTEXT_FAILED" value="A fatal error occurred while opening the system %1 cryptographic module. Operations that require the SSL or TLS cryptographic protocols will not work correctly. The error code is %2." />
        <string id="event_SSLEVENT_CREATE_CRED" value="Creating a TLS %3 credential.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_CRED_PROPERTIES" value="The TLS %1 credential's private key has the following properties:%n%n   CSP name: %2%n   CSP type: %3%n   Key name: %4%n   Key Type: %5%n   Key Flags: %6%n%n The attached data contains the certificate." />
        <string id="event_SSLEVENT_NO_PRIVATE_KEY" value="The TLS %3 credential's certificate does not have a private key information property attached to it. This most often occurs when a certificate is backed up incorrectly and then later restored. This message can also indicate a certificate enrollment failure.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_CRED_ACQUIRE_CONTEXT_FAILED" value="A fatal error occurred when attempting to access the TLS %3 credential private key. The error code returned from the cryptographic module is %4. The internal error state is %5.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_CREATE_CRED_FAILED" value="A fatal error occurred while creating a TLS %3 credential. The internal error state is %4.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_GET_CERT_CHAIN_FAILURE" value="The TLS %3 specified certificate's chain could not be retrieved:%n%n   Failure Status: %4%n   Flags: %5%n%n The attached data contains the certificate.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_INCOMPLETE_CERT_CHAIN_FAILURE" value="The TLS %3 specified certificate's chain is incomplete:%n%n   Failure Status: %4%n%n This can cause trust validation failures or interoperability problems. For more information see KB 954755%n The attached data contains the certificate.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_OCSP_STATUS_RETRIEVAL_FAILURE" value="Could not retrieve an OCSP response.%n%n   The Failure Reason is: %1%n    The OCSP Url is: %2%n   The previous OCSP response contained the following times:%n      ThisUpdate: %3%n      NextUpdate: %4%n%nThe attached data contains the certificate." />
        <string id="event_SSLEVENT_NO_DEFAULT_SERVER_CRED" value="No suitable default server credential exists on this system. This will prevent server applications that expect to make use of the system default credentials from accepting SSL connections. An example of such an application is the directory server. Applications that manage their own credentials, such as the internet information server, are not affected by this.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_NO_CIPHERS_SUPPORTED" value="No supported cipher suites were found when initiating a TLS connection. This indicates a configuration problem with the client application and/or the installed cryptographic modules. The TLS connection request has failed.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_CIPHER_MISMATCH" value="An %3 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The TLS connection request has failed.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_NO_CLIENT_CERT_FOUND" value="The remote server has requested TLS client authentication, but no suitable client certificate could be found. An anonymous connection will be attempted. This TLS connection request may succeed or fail, depending on the server's policy settings.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_BOGUS_SERVER_CERT" value="The certificate received from the remote server has not validated correctly. The error code is %3. The TLS connection request has failed. The attached data contains the server certificate.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_BOGUS_CLIENT_CERT" value="The certificate received from the remote client application has not validated correctly. The error code is %3. The attached data contains the client certificate.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_FAST_MAPPING_FAILURE" value="The certificate received from the remote client application is not suitable for direct mapping to a client system account, possibly because the authority that issuing the certificate is not sufficiently trusted. The error code is %3. The attached data contains the client certificate.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_CERT_MAPPING_FAILURE" value="The certificate received from the remote client application was not successfully mapped to a client system account. The error code is %3. This is not necessarily a fatal error, as the server application may still find the certificate acceptable.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_HANDSHAKE_INFO" value="A TLS %1 handshake completed successfully. The negotiated cryptographic parameters are as follows.%n%n   Protocol version: %2%n   CipherSuite: %3%n   Exchange strength: %4 bits%n   Context handle: %5%n   Target name: %6%n   Local certificate subject name: %7%n   Remote certificate subject name: %8" />
        <string id="event_SSLEVENT_EXPIRED_SERVER_CERT" value="The certificate received from the remote server has either expired or is not yet valid. The TLS connection request has failed. The attached data contains the server certificate.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_UNTRUSTED_SERVER_CERT" value="The certificate received from the remote server was issued by an untrusted certificate authority. Because of this, none of the data contained in the certificate can be validated. The TLS connection request has failed. The attached data contains the server certificate.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_REVOKED_SERVER_CERT" value="The certificate received from the remote server has been revoked. This means that the certificate authority that issued the certificate has invalidated it. The TLS connection request has failed. The attached data contains the server certificate.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_NAME_MISMATCHED_SERVER_CERT" value="The certificate received from the remote server does not contain the expected name. It is therefore not possible to determine whether we are connecting to the correct server. The server name we were expecting is %3. The TLS connection request has failed. The attached data contains the server certificate.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_RECEIVE_FATAL_ALERT" value="A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is %3.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_GENERATE_FATAL_ALERT" value="A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal alert code is %3.%n%n   Target name: %5%n%n The SSPI client process is %2 (PID: %1).%nThe TLS alert registry can be found at http://www.iana.org/assignments/tls-parameters/tls-parameters.xhtml#tls-parameters-6" />
        <string id="event_SSLEVENT_ISSUER_LIST_OVERFLOW_FAILURE" value="When asking for client authentication, this server sends a list of trusted certificate authorities to the client. The client uses this list to choose a client certificate that is trusted by the server. Currently, this server trusts so many certificate authorities that the list has grown too long. This list has thus been truncated. The administrator of this machine should review the certificate authorities trusted for client authentication and remove those that do not really need to be trusted.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_DTLS_COOKIE_VERIFY_FAILED" value="Verification of the DTLS connection request failed.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_DTLS_RECORD_OUTSIDE_OF_RECV_WINDOW" value="DTLS record was rejected because it is outside of current receive window.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_DTLS_DUPLICATE_RECORD" value="A DTLS record was rejected because it is a duplicate of a previously received record.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_DTLS_RETRANSMIT_REQUESTED" value="The retransmission of DTLS handshake messages has been requested.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_SSLEVENT_SESSION_TICKET_MISCONFIGURATION" value="The key material used to protect TLS Session Tickets was not found at %3.%n The SSPI client process is %2 (PID: %1)." />
        <string id="event_NEGOTIATE_DOWNGRADE_DETECTED" value="The Security System detected an authentication error for the server %1. The failure code from authentication protocol %2 was %3." />
        <string id="event_NEGOTIATE_INVALID_SERVER" value="The Security System could not establish a secured connection with the server %1. No authentication protocol was available." />
        <string id="event_NEGOTIATE_UNBALANCED_EXCHANGE" value="The Security System was unable to authenticate to the server %1 because the server has completed the authentication, but the client authentication protocol %2 has not." />
        <string id="event_NEGOTIATE_UNKNOWN_PACKAGE" value="The Security System received an authentication attempt with an unknown authentication protocol. The request has failed." />
        <string id="event_NEGOTIATE_PACKAGE_SELECTED" value="The Security System has selected %2 for the authentication protocol to server %1." />
        <string id="event_NEGOTIATE_MESSAGE_DECODED" value="The Security System has received an authentication attempt, and determined that the protocol %1 preferred by the client is acceptable." />
        <string id="event_NEGOTIATE_RAW_PACKET" value="The Security System has received an authentication request directly for authentication protocol %1." />
        <string id="event_NEGOTIATE_UNKNOWN_PACKET" value="The Security System has received an authentication request that could not be decoded. The request has failed." />
        <string id="event_NEGOTIATE_MESSAGE_DECODED_NO_TOKEN" value="The Security System has received an authentication attempt, and determined that the protocol %1 is the common protocol." />
        <string id="event_LSA_ENCRYPTED_SECRET_RETURNED" value="A secret object private to LSA was queried by a client. This object was returned in encrypted format for security reasons." />
        <string id="event_LSA_CENTRAL_ACCESS_POLICIES_MISSING" value="An error occurred while retrieving new Central Access Policies for this machine.%n%nCould not retrieve policies for the following DNs:%n%1" />
        <string id="event_LSA_BAD_CENTRAL_ACCESS_RULE" value="An error occurred while processing new Central Access Policies for this machine. Validation failed for the following Central Access Rule referenced by one or more of the Central Access Policies:%n%n%tError:%t%t%1%n%n%tName:%t%t%2%n%tDescription:%t%3" />
        <string id="event_LSA_CREDENTIAL_GUARD_PACKAGE_AUDIT" value="LSA package is not signed as expected. This can cause unexpected behavior with Credential Guard.%n%nPackageName: %1" />
        <string id="event_LSA_CREDENTIAL_GUARD_AUTO_ENABLEMENT" value="Credential Guard auto enablement status.%n%nHardware Requirements for Virtualization Based Security:%t%1%nDomain Joined:%t%2%nAzure AD Joined:%t%3%n Licensed for Credential Guard:%t%4%nDomain Controller:%t%5" />
        <string id="event_LSA_POSSIBLE_TOKEN_LEAK" value="LogonSession alive after interactive user logoff. Indicates a possible token leak in one of the services. %nLogon ID:%1%nAccount Name:%2%nDomain Name:%3%n" />
        <string id="event_LSA_PACKAGE_NO_CREDENTIAL" value="The security package does not cache the credentials needed to authenticate to the server.%n%nPackage Name:%t%1%nUser Name:%t%2%nDomain Name:%t%3%nServer Name:%t%4%nProtected User:%t%5%nError Code:%t%6%n" />
        <string id="event_LSA_PACKAGE_POST_LOGOFF_REQUEST" value="A security package received a network logon request after the logoff completed.%n%nUser Name:%t%1%nDomain Name:%t%2%nLogon ID:%t%3%nLogoff Time:%t%4%nPID:%t%5%nProgram:%t%6%nPrincipal Name:%t%7%nServer Name:%t%8%nPackage Name:%t%9%nCall Type:%t%10%nError Code:%t%11%n" />
        <string id="event_LSA_GROUPS_AT_LOGON" value="Groups assigned to a new logon.%n%nNew Logon:%n%tSecurity ID:%t%t%1%n%tAccount Name:%t%t%2%n%tAccount Domain:%t%t%3%n%tLogon ID:%t%t%4%n%tLogon GUID:%t%t%5%n%nEvent in sequence:%t%t%6 of %7%n%nGroup Membership:%t%t%8" />
        <string id="event_LSA_CLAIMS_AT_LOGON" value="Claims assigned to a new logon.%n%nNew Logon:%n%tSecurity ID:%t%t%1%n%tAccount Name:%t%t%2%n%tAccount Domain:%t%t%3%n%tLogon ID:%t%t%4%n%tLogon GUID:%t%t%5%n%n%n%tLogon Type:%t%t%6%n%n%n%nEvent in sequence:%t%t%7 of %8%n%nUser Claims:%t%t%9%n%nDevice Claims:%t%t%10%n%nThis event is generated when a new logon session is created and the user token associated with it contains user and/or device claims. The New Logon fields indicate the account that was logged on. If all the user and device claims in the user token cannot be accommodated in a single event, multiple such events are generated. The Event in sequence field indicates how many more events are generated for this logon session. Each user or device claim is represented in the following format:%n%n%tClaimID ClaimTypeID : Value1, Value2 … %n%nThe common claim types are: 0 (Invalid Type), 1 (64-bit Integer, 2 (Unsigned 64-bit Integer), 3 (String), 4 (FQBN), 5 (SID), 6 (Boolean) and 16 (Blob). If the claim value exceeds the max allowed length then the string is terminated by ..." />
        <string id="event_LSA_USER_LOGOFF_NOTIFICATION" value="User %1 logged off notification is received.%n%nLogonId:%t%2%nAuthorityName:%t%3%nAccountName:%t%4%nTimeout:%t%5 seconds%n" />
        <string id="event_LSA_PACKAGE_NOT_CACHE_LOGON_USER" value="The security package does not cache the user's sign on credentials.%n%nPackage Name:%t%1%nUser Name:%t%2%nDomain Name:%t%3%nProtected User:%t%4%n" />
        <string id="event_LSA_CONFIGURE_AUTOLOGON_CREDENTIALS_SUCCESS" value="Automatic restart sign on successfully configured the autologon credentials for:%n%n%tAccount Name:%t%t%1%n%tAccount Domain:%t%t%2" />
        <string id="event_LSA_DELETE_AUTOLOGON_CREDENTIALS" value="Automatic restart sign on successfully deleted autologon credentials from LSA memory" />
        <string id="event_LSA_CONFIGURE_AUTOLOGON_CREDENTIALS_FAILURE" value="Automatic restart sign on failed to configure the autologon credentials with error:%n%n%1" />
        <string id="event_LSA_CREDENTIAL_GUARD_NOT_LICENSED" value="Credential Guard is configured to run, but is not licensed. Credential Guard was not started." />
        <string id="event_LSA_LSAISO_UEFI_READ_ERROR" value="Error reading Credential Guard (LsaIso.exe) UEFI configuration: %1" />
        <string id="event_LSA_LSAISO_LAUNCH_FAILURE" value="LsaIso.exe, the host process for Credential Guard and Key Guard, failed to launch: %1" />
        <string id="event_LSA_LSAISO_CONFIG" value="Credential Guard configuration: %1, %2, %3" />
        <string id="event_LSA_LSAISO_KEYGUARD" value="Key Guard was started and will protect VSM-isolated keys." />
        <string id="event_LSA_LSAISO_CREDGUARD" value="Credential Guard was started and will protect LSA credentials." />
        <string id="event_LSA_LSAISO_SK_NOT_PRESENT" value="Credential Guard is configured but the secure kernel is not running; continuing without Credential Guard." />
        <string id="event_LSA_LSAISO_MACHINE_IDENTITY_ISOLATION_FALLBACK" value="IUM bound machine password is present but falling back to LSA bound password.%nCredential Guard running status: %1%nIUM bound machine password validity: %2%n" />
        <string id="event_LSA_MACHINE_CREDENTIAL_STATUS" value="Status of the machine credential:%n%nCredential Guard running: %1%nGroup Policy configuration: %2%nMachine password source: %3%nIUM bound machine password validity: %4%nMachine certificate present: %5%n" />
        <string id="event_LSA_MACHINE_ID_PARTIAL_MISMATCH" value="There is a partial mismatch in the machine ID. This indicates that the ticket issued by user %1 has either been manipulated or it belongs to a different boot session. Failing authentication.%n%nNOTE:%nThis can also happen if the machine was cloned without using sysprep. More information can be found at https://go.microsoft.com/fwlink/?linkid=2349106%n;" />
        <string id="event_LSA_ALLOW_UAC_BYPASS" value="UAC bypass via kerberos vulnerability is explicitly allowed. A kerberos loopback ticket can be manipulated to gain admin privileges. This is a security risk.%n" />
        <string id="event_LSA_PDC_FULL_TRUSTSCAN_SUCCESS" value="The PDC completed an automatic trust scan operation for all trusts with no errors.%n%nMore information can be found at https://go.microsoft.com/fwlink/?linkid=2162089." />
        <string id="event_LSA_PDC_FULL_TRUSTSCAN_FAILURE" value="The PDC completed an automatic trust scan operation for all trusts and encountered at least one error.%n%nMore information can be found at https://go.microsoft.com/fwlink/?linkid=2162089." />
        <string id="event_LSA_PDC_MANUAL_TRUSTSCAN_SUCCESS" value="The PDC completed an administrator-requested trust scan operation for the trust '%1' with no errors.%n%nMore information can be found at https://go.microsoft.com/fwlink/?linkid=2162089." />
        <string id="event_LSA_PDC_MANUAL_TRUSTSCAN_NOTFOUND" value="The PDC was unable to find the specified trust '%1' to scan. The trust either does not exist or it is neither an inbound or bidirectional trust.%n%nMore information can be found at https://go.microsoft.com/fwlink/?linkid=2162089." />
        <string id="event_LSA_PDC_MANUAL_TRUSTSCAN_FAILURE" value="The PDC completed an administrator-requested trust scan operation for the trust '%1' and encountered an error. The security of the local forest is unaffected by this error. The trusting forest may be at risk until the issue is resolved.%n%nMore information can be found at https://go.microsoft.com/fwlink/?linkid=2162089." />
        <string id="event_LSA_PDC_SPECIFIC_TRUST_SCAN_FAILURE" value="The PDC encountered an error trying to scan the named trust. The security of the local forest is unaffected by this error. The trusting forest may be at risk until the issue is resolved.%n%nTrust: %1%n%nError: %2(%3)%n%nMore information can be found at https://go.microsoft.com/fwlink/?linkid=2162089." />
        <string id="event_LSA_PDC_SPECIFIC_TRUSTSCAN_SUCCESS" value="The PDC completed a background trust scan operation of the named trust.%n%nTrust: %1%n%nMore information can be found at https://go.microsoft.com/fwlink/?linkid=2162089." />
        <string id="event_LSA_CREDENTIAL_GUARD_CREDMAN_AUDIT" value="Possible use of roaming Credential Manager credentials with Credential Guard detected. This feature is unsupported. Refer to Credential Guard documentation for more details." />
        <string id="msg_LSAP_UNUSED_MESSAGE" value="MessageIdTypedef=DWORD" />
        <string id="msg_LSAP_SID_NAME_NULL" value="NULL SID" />
        <string id="msg_LSAP_SID_NAME_WORLD" value="Everyone" />
        <string id="msg_LSAP_SID_NAME_LOCAL" value="LOCAL" />
        <string id="msg_LSAP_SID_NAME_LOCAL_LOGON" value="CONSOLE LOGON" />
        <string id="msg_LSAP_SID_NAME_CREATOR_OWNER" value="CREATOR OWNER" />
        <string id="msg_LSAP_SID_NAME_CREATOR_GROUP" value="CREATOR GROUP" />
        <string id="msg_LSAP_SID_NAME_NT_DOMAIN" value="NT Pseudo Domain" />
        <string id="msg_LSAP_SID_NAME_NT_AUTHORITY" value="NT AUTHORITY" />
        <string id="msg_LSAP_SID_NAME_DIALUP" value="DIALUP" />
        <string id="msg_LSAP_SID_NAME_NETWORK" value="NETWORK" />
        <string id="msg_LSAP_SID_NAME_BATCH" value="BATCH" />
        <string id="msg_LSAP_SID_NAME_INTERACTIVE" value="INTERACTIVE" />
        <string id="msg_LSAP_SID_NAME_SERVICE" value="SERVICE" />
        <string id="msg_LSAP_SID_NAME_BUILTIN" value="BUILTIN" />
        <string id="msg_LSAP_SID_NAME_SYSTEM" value="SYSTEM" />
        <string id="msg_LSAP_SID_NAME_ANONYMOUS" value="ANONYMOUS LOGON" />
        <string id="msg_LSAP_SID_NAME_CREATOR_OWNER_SERVER" value="CREATOR OWNER SERVER" />
        <string id="msg_LSAP_SID_NAME_CREATOR_GROUP_SERVER" value="CREATOR GROUP SERVER" />
        <string id="msg_LSAP_SID_NAME_SERVER" value="ENTERPRISE DOMAIN CONTROLLERS" />
        <string id="msg_LSAP_SID_NAME_SELF" value="SELF" />
        <string id="msg_LSAP_SID_NAME_AUTHENTICATED_USER" value="Authenticated Users" />
        <string id="msg_LSAP_SID_NAME_RESTRICTED" value="RESTRICTED" />
        <string id="msg_LSAP_SID_NAME_INTERNET" value="Internet$" />
        <string id="msg_LSAP_SID_NAME_TERMINAL_SERVER" value="TERMINAL SERVER USER" />
        <string id="msg_LSAP_SID_NAME_PROXY" value="PROXY" />
        <string id="msg_LSAP_SID_NAME_LOCALSERVICE" value="LOCAL SERVICE" />
        <string id="msg_LSAP_SID_NAME_NETWORKSERVICE" value="NETWORK SERVICE" />
        <string id="msg_LSAP_SID_NAME_REMOTE_INTERACTIVE" value="REMOTE INTERACTIVE LOGON" />
        <string id="msg_LSAP_SID_NAME_USERS" value="USERS" />
        <string id="msg_LSAP_SID_NAME_NTLM_AUTH" value="NTLM Authentication" />
        <string id="msg_LSAP_SID_NAME_DIGEST_AUTH" value="Digest Authentication" />
        <string id="msg_LSAP_SID_NAME_SCHANNEL_AUTH" value="SChannel Authentication" />
        <string id="msg_LSAP_SID_NAME_LIVESSP_AUTH" value="Microsoft Account Authentication" />
        <string id="msg_LSAP_SID_NAME_THIS_ORGANIZATION" value="This Organization" />
        <string id="msg_LSAP_SID_NAME_OTHER_ORGANIZATION" value="Other Organization" />
        <string id="msg_LSAP_SID_NAME_THIS_ORG_CERT" value="This Organization Certificate" />
        <string id="msg_LSAP_SID_NAME_IUSER" value="IUSR" />
        <string id="msg_LSAP_SID_NAME_MANDATORY_LABEL_AUTHORITY" value="Mandatory Label" />
        <string id="msg_LSAP_SID_NAME_MANDATORY_LABEL_UNTRUSTED" value="Untrusted Mandatory Level" />
        <string id="msg_LSAP_SID_NAME_MANDATORY_LABEL_LOW" value="Low Mandatory Level" />
        <string id="msg_LSAP_SID_NAME_MANDATORY_LABEL_MEDIUM" value="Medium Mandatory Level" />
        <string id="msg_LSAP_SID_NAME_MANDATORY_LABEL_MEDIUM_PLUS" value="Medium Plus Mandatory Level" />
        <string id="msg_LSAP_SID_NAME_MANDATORY_LABEL_HIGH" value="High Mandatory Level" />
        <string id="msg_LSAP_SID_NAME_MANDATORY_LABEL_SYSTEM" value="System Mandatory Level" />
        <string id="msg_LSAP_SID_NAME_MANDATORY_LABEL_PROTECTED_PROCESS" value="Protected Process Mandatory Level" />
        <string id="msg_LSAP_SID_NAME_CREATOR_OWNER_RIGHTS" value="OWNER RIGHTS" />
        <string id="msg_LSAP_SID_NAME_WRITE_RESTRICTED" value="WRITE RESTRICTED" />
        <string id="msg_LSAP_SID_NAME_ERODC" value="ENTERPRISE READ-ONLY DOMAIN CONTROLLERS BETA" />
        <string id="msg_LSAP_SID_NAME_ALL_APP_PACKAGES" value="ALL APPLICATION PACKAGES" />
        <string id="msg_LSAP_SID_NAME_APP_PACKAGE_AUTHORITY" value="APPLICATION PACKAGE AUTHORITY" />
        <string id="msg_LSAP_SID_NAME_CAPABILITY_INTERNET_CLIENT" value="Your Internet connection" />
        <string id="msg_LSAP_SID_NAME_CAPABILITY_INTERNET_CLIENT_SERVER" value="Your Internet connection, including incoming connections from the Internet" />
        <string id="msg_LSAP_SID_NAME_CAPABILITY_PRIVATE_NETWORK_CLIENT_SERVER" value="Your home or work networks" />
        <string id="msg_LSAP_SID_NAME_CAPABILITY_PICTURES_LIBRARY" value="Your pictures library" />
        <string id="msg_LSAP_SID_NAME_CAPABILITY_VIDEOS_LIBRARY" value="Your videos library" />
        <string id="msg_LSAP_SID_NAME_CAPABILITY_MUSIC_LIBRARY" value="Your music library" />
        <string id="msg_LSAP_SID_NAME_CAPABILITY_DOCUMENTS_LIBRARY" value="Your documents library" />
        <string id="msg_LSAP_SID_NAME_CAPABILITY_ENTERPRISE_AUTHENTICATION" value="Your Windows credentials" />
        <string id="msg_LSAP_SID_NAME_CAPABILITY_SHARED_USER_CERTIFICATES" value="Software and hardware certificates or a smart card" />
        <string id="msg_LSAP_SID_NAME_CAPABILITY_REMOVABLE_STORAGE" value="Removable storage" />
        <string id="msg_LSAP_SID_NAME_CAPABILITY_APPOINTMENTS" value="Your Appointments" />
        <string id="msg_LSAP_SID_NAME_CAPABILITY_CONTACTS" value="Your Contacts" />
        <string id="msg_LSAP_SID_NAME_USER_MODE_DRIVERS" value="USER MODE DRIVERS" />
        <string id="msg_LSAP_SID_NAME_SENTINEL_CLAIMS" value="Claims Valid" />
        <string id="msg_LSAP_SID_NAME_SENTINEL_COMPOUND" value="Compound Identity Present" />
        <string id="msg_LSAP_SID_NAME_AUTHENTICATION_AUTHORITY_ASSERTED" value="Authentication authority asserted identity" />
        <string id="msg_LSAP_SID_NAME_AUTHENTICATION_SERVICE_ASSERTED" value="Service asserted identity" />
        <string id="msg_LSAP_SID_NAME_AUTHENTICATION_FRESHNESS" value="Fresh public key identity" />
        <string id="msg_LSAP_SID_NAME_AUTHENTICATION_KEY_TRUST" value="Key trust identity" />
        <string id="msg_LSAP_SID_NAME_AUTHENTICATION_KEY_PROPERTY_MFA" value="Key property multi-factor authentication" />
        <string id="msg_LSAP_SID_NAME_AUTHENTICATION_KEY_PROPERTY_ATTESTATION" value="Key property attestation" />
        <string id="msg_LSAP_SID_NAME_LOCAL_ACCOUNT" value="Local account" />
        <string id="msg_LSAP_SID_NAME_LOCAL_ACCOUNT_AND_ADMINISTRATOR" value="Local account and member of Administrators group" />
        <string id="msg_LSAP_SID_NAME_DEFAULT_ACCOUNT" value="DefaultAccount" />
        <string id="msg_LSAP_SID_NAME_DEFAULT_ACCOUNT_GROUP" value="System Managed Accounts Group" />
        <string id="msg_LSAP_DEFAULT_DOMAIN_NAME" value="LsaSetupDomain" />
        <string id="msg_SSLEVENTTEXT_CLIENT" value="client" />
        <string id="msg_SSLEVENTTEXT_SERVER" value="server" />
        <string id="msg_CRED_TEXT_ENTERPRISECRED_DATA" value="Enterprise Credential Data" />
        <string id="msg_CRED_TEXT_LOCALCRED_DATA" value="Local Credential Data" />
        <string id="msg_LSAP_SID_NAME_CLOUDAP_AUTH" value="Cloud Account Authentication" />
        <string id="event_LOGON_CACHE_DISABLED_MSG" value="Logon cache was disabled. Intermittent authentication failures may result during periods of network latency or interrupts. Please contact your system administrator." />
        <string id="event_LOGON_ENTRY_DELETED_MSG" value="A failed logon attempt has caused a logon cache entry for user %1 to be deleted. The authentication package was %2, and the error message was %3." />
        <string id="event_LOGON_ENTRY_FLUSHED_MSG" value="A logon cache entry for user %1 was the oldest entry and was removed. The timestamp of this entry was %2." />
        <string id="event_LSA_NO_TARGET_NAME" value="The program %2, with the assigned Process ID %1, supplied a NULL or empty target name for the pszTargetName parameter when calling the InitializeSecurityContext API to initiate an outbound NTLM security context. This is a security risk when mutual authentication is required.%n %n To help protect against a malicious attack, make your code more secure. To do this, change the program so that it specifies a target name in the pszTargetName parameter field, and then recompile the code." />
        <string id="event_LSA_LOOPBACK_REJECTED" value="The program %2, with the assigned process ID %1, could not authenticate locally by using the target name %3. The target name used is not valid. A target name should refer to one of the local computer names, for example, the DNS host name.%n %n Try a different target name." />
        <string id="event_LSA_NTLM_USAGE" value="Microsoft Windows Server has detected that NTLM authentication is presently being used between clients and this server. This event occurs once per boot of the server on the first time a client uses NTLM with this server.%n %nNTLM is a weaker authentication mechanism. Please check:%n %n      Which applications are using NTLM authentication?%n      Are there configuration issues preventing the use of stronger authentication such as Kerberos authentication?%n      If NTLM must be supported, is Extended Protection configured?%n %nDetails on how to complete these checks can be found at http://go.microsoft.com/fwlink/?LinkId=225699." />
        <string id="event_LSA_NTLM_USAGE_INFO" value="Microsoft Windows Server has detected that NTLM authentication is being used between clients and this server. This event occurs once per boot of the server on the first time a client uses NTLM with this server.%n %nNTLM is a weaker authentication mechanism. Please check:%n %n      Which applications are using NTLM authentication?%n      Are there configuration issue preventing the use stronger authentication such as Kerberos authentication?%n      If NTLM must be supported, is Extended Protection configured?%n %nDetails on how to complete these checks can be found at http://go.microsoft.com/fwlink/?LinkId=225699." />
        <string id="event_LSA_INVALID_TARGET_INFO" value="An authentication request for package %1 was rejected because the target information was invalid.  The authentication request did not match the target name of %2." />
        <string id="event_LSA_NO_COMMON_VERSION" value="A CredSSP authentication to %1 failed to negotiate a common protocol version.  The remote host offered version %2 which is not permitted by Encryption Oracle Remediation.%n%nSee https://go.microsoft.com/fwlink/?linkid=866660 for more information." />
        <string id="msg_LSAP_SID_NAME_ALL_RESTRICTED_APP_PACKAGES" value="ALL RESTRICTED APPLICATION PACKAGES" />
        <string id="msg_LSAP_SID_NAME_WINDOW_MANAGER_GROUP" value="Window Manager Group" />
        <string id="msg_LSAP_SID_NAME_DEVICE_OWNERS_GROUP" value="Device Owners" />
        <string id="msg_LSAP_SID_NAME_RESTRICTED_SERVICES" value="RESTRICTED SERVICES" />
        <string id="msg_LSAP_SID_NAME_ALL_RESTRICTED_SERVICES" value="ALL RESTRICTED SERVICES" />
      </stringTable>
    </resources>
  </localization>
</assembly>