Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit

Anonymous
2019-04-28T20:45:27+00:00

Immediately after every reboot of Win 10 Pro 64-bit version 1803, in Event Viewer, there are between two and four Audit Failures for something related to Cryptography.  So my Win 10 machine is insecure?  I have run sfc /scannow  and  Dism /Online /Cleanup-Image /RestoreHealth many times, with no luck.  And I hardly even use my Win 10 machine - there are almost no apps on it yet.  My actual Win 10 build is 17134.706

Here are the latest five Cryptography-related Audit Failures, from two reboots:

LATEST OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 12:27:52 PM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        DESKTOP-3#####N[My user name]

    Account Name:        [My user name]

    Account Domain:        DESKTOP-3#####N

    Logon ID:        0x3EC24

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    Microsoft Connected Devices Platform device certificate

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T16:27:52.339705400Z" />

    <EventRecordID>19582</EventRecordID>

    <Correlation />

    <Execution ProcessID="880" ThreadID="948" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-21-[My Identifier 10-9-10 digits]-1001</Data>

    <Data Name="SubjectUserName">[My user name]</Data>

    <Data Name="SubjectDomainName">DESKTOP-3#####N</Data>

    <Data Name="SubjectLogonId">0x3ec24</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">Microsoft Connected Devices Platform device certificate</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

FOURTH OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 12:26:51 PM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        LOCAL SERVICE

    Account Name:        LOCAL SERVICE

    Account Domain:        NT AUTHORITY

    Logon ID:        0x3E5

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    [Hex number]

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T16:26:51.704606400Z" />

    <EventRecordID>19552</EventRecordID>

    <Correlation />

    <Execution ProcessID="880" ThreadID="1004" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-19</Data>

    <Data Name="SubjectUserName">LOCAL SERVICE</Data>

    <Data Name="SubjectDomainName">NT AUTHORITY</Data>

    <Data Name="SubjectLogonId">0x3e5</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">[Hex number]</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

THIRD OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 11:29:28 AM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        DESKTOP-3#####N[My user name]

    Account Name:        [My user name]

    Account Domain:    DESKTOP-3#####N

    Logon ID:        0x3EF94

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    Microsoft Connected Devices Platform device certificate

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T15:29:28.196237300Z" />

    <EventRecordID>19387</EventRecordID>

    <Correlation />

    <Execution ProcessID="884" ThreadID="928" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-21-[My Identifier 10-9-10 digits]-1001</Data>

    <Data Name="SubjectUserName">[My user name]</Data>

    <Data Name="SubjectDomainName">DESKTOP-3#####N</Data>

    <Data Name="SubjectLogonId">0x3ef94</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">Microsoft Connected Devices Platform device certificate</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

SECOND OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 11:28:27 AM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        LOCAL SERVICE

    Account Name:        LOCAL SERVICE

    Account Domain:        NT AUTHORITY

    Logon ID:        0x3E5

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    [Hex number]

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T15:28:27.709849300Z" />

    <EventRecordID>19363</EventRecordID>

    <Correlation />

    <Execution ProcessID="884" ThreadID="992" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-19</Data>

    <Data Name="SubjectUserName">LOCAL SERVICE</Data>

    <Data Name="SubjectDomainName">NT AUTHORITY</Data>

    <Data Name="SubjectLogonId">0x3e5</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">[Hex number]</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

FIRST OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 11:28:27 AM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        LOCAL SERVICE

    Account Name:        LOCAL SERVICE

    Account Domain:        NT AUTHORITY

    Logon ID:        0x3E5

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    [Hex number]

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T15:28:27.709849300Z" />

    <EventRecordID>19363</EventRecordID>

    <Correlation />

    <Execution ProcessID="884" ThreadID="992" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-19</Data>

    <Data Name="SubjectUserName">LOCAL SERVICE</Data>

    <Data Name="SubjectDomainName">NT AUTHORITY</Data>

    <Data Name="SubjectLogonId">0x3e5</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">[Hex number]</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

So, what the *** are these, and how do we fix?  No guesses - just the real fix.


glnzglnz

☺ In the office, Dell Optiplex 7040 with 8GB RAM, Win 7 Pro 64-bit and Office 2010

☻ At home, Dell Optiplex 7010 with 16GB RAM dual-booting Win 7 Pro 64-bit (now with Office 365 Home) and Win 10 Pro 64-bit

♥ Also still have Dell Optiplex 755 with 4GB RAM with Win XP Pro SP3 (which still gets updates with the POS hack) and Office 2003

Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

48 answers

Sort by: Oldest
  1. Anonymous
    2019-05-18T03:33:42+00:00

    Coni - FYI - On my Win 10 Pro 64-bit, I do not yet have any version of Office.  But Win 10 comes with OneDrive and so it starts up, and my user name with that is [MyName]@outlook.com .

    From what I posted above six above, doesn't it look like my Audit Failures are related to OneDrive simply running and syncing a very few files?  I can't tell for sure, and I certainly don't know what to do about it.

    One more clue - my Win 10 machine actually dual boots the Win 10 and Win 7 Pro 64-bit.  Might that have anything to do with it?  But your machine is only Win 10, yes?

    Very frustrating.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2019-05-18T17:19:24+00:00

    It is very frustrating but all of my searches come up empty with a fix. Only Microsoft knows for sure, or maybe they don't and that is why they have kept quiet on this subject. If you do a search for event 5061 you find many people with the audit failure and not all the same reasons ( Nvidia for example) It could be a one drive issue where as we upgrade something is not changed in the registry, or install and uninstall programs the synced file will still remain and causes an audit failure. Your guess is as good as mine. When I do a clean install of 1903 I will report here if it clears the audit. Some say it is expired certificates and some say phone home programs cause these audits but nobody has ever come up with a fix as it really could be a number of things. My machine is only 8 months old and came with windows 10 on it. There is one post here from 2015 where 170 people marked me too on the "I have the same problem" . I found only one post on it in feedback hub but I really don't think there are too many people that use event viewer or the feedback hub.

    Here is from a search for this audit failure. Lots comes up but no solutions. I have read and read till I am exhausted. Like I said I do not seem to have problems with security because of it but who knows what underlying problems there really may be.

    Here is search.

    https://www.bing.com/search?q=event+5061+audit+failure&form=EDGNB3&mkt=en-us&httpsmsn=1&plvar=0&refig=9ab2eb9a5fb646f4a472a25864512521&sp=2&qs=RI&pq=audit+5061&sk=SC1&sc=2-10&cvid=9ab2eb9a5fb646f4a472a25864512521&cc=US&setlang=en-US

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2019-05-18T20:54:22+00:00

    Coni - thanks for very informative post and link.

    I'm on 1803 and I recall you wrote you are on 1809 and also have the AUDIT FAILURE issue.

    Yes, I'll be very curious to know whether your update to 1903 helps.  Please remember to come back here after that.

    I've also posted on Technet where, ten days ago, a MS moderator said she'd reach out to a MS engineer, but she hasn't posted since (and I've replied twice to nudge her, including with a copy of your post above).

    I was about to start migrating my life from Win 7 to Win 10, but it seems unsecure with these AUDIT FAILURES.  And also start planning the same migrate for my wife's SOHO. 

    Very frustrating.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2019-05-18T21:46:54+00:00

    Coni and Larry - A bit of extra info.

    Before rebooting my Win 10 just now, I want to Task Manager - Startup and DISABLED OneDrive from starting on boot.  Then I rebooted.

    The Audit Failures occurred again! 

    However, a different repeating error did not occur.  The following error has also been recurring on every reboot but NOT this time with OneDrive disabled on startup:

    Log Name:      Microsoft-Windows-Kernel-EventTracing/Admin

    Source:        Microsoft-Windows-Kernel-EventTracing

    Date:          5/18/2019 5:27:31 PM

    Event ID:      2

    Task Category: Session

    Level:         Error

    Keywords:      Session

    User:          DESKTOP-3*****N[My Name]

    Computer:      DESKTOP-3*****N

    Description:

    **Session "Cloud Files Diagnostic Event Listener" failed to start with the following error:**0xC0000022

    Event Xml:

    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

      <System>

        <Provider Name="Microsoft-Windows-Kernel-EventTracing" Guid="{B675EC37-BDB6-4648-BC92-F3FDC74D3CA2}" />

        <EventID>2</EventID>

        <Version>0</Version>

        <Level>2</Level>

        <Task>2</Task>

        <Opcode>12</Opcode>

        <Keywords>0x8000000000000010</Keywords>

        <TimeCreated SystemTime="2019-05-18T21:27:31.169215900Z" />

        <EventRecordID>149</EventRecordID>

        <Correlation />

        <Execution ProcessID="7712" ThreadID="8300" />

        <Channel>Microsoft-Windows-Kernel-EventTracing/Admin</Channel>

        <Computer>DESKTOP-3*****N</Computer>

        <Security UserID="S-1-5-21-[My ID 10-9-10 digits]-1001" />

      </System>

      <EventData>

        <Data Name="SessionName">Cloud Files Diagnostic Event Listener</Data>

        <Data Name="FileName">

        </Data>

        <Data Name="ErrorCode">3221225506</Data>

        <Data Name="LoggingMode">4194560</Data>

      </EventData>

    </Event>

    Well, I don't suppose this is terribly helpful, but any thoughts?

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2019-05-19T00:54:54+00:00

    Yes I ran across both of your posts on TechNet. It is pretty bad when TechNet will not or cannot give an answer.

    Yes that error has been seen by me too. Cloud Files=OneDrive.

    Here is a search for that error.

    https://www.bing.com/search?q=Cloud+Files+Diagnostic+Event+Listener%22+failed+to+start+with+the+following+error%3A+0xC0000022&form=EDGNB1&mkt=en-us&httpsmsn=1&plvar=0&refig=f2973b37e78b48debc4cf1fa8ac4f5fe

    I will let you know if this stuff is resolved with1903 as upgraded. If not then after clean install.

    The only problem with staying with Windows 7 (one of the best) is support will stop for it and that will mean no more security updates for it.

    Was this answer helpful?

    0 comments No comments