Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit

Anonymous
2019-04-28T20:45:27+00:00

Immediately after every reboot of Win 10 Pro 64-bit version 1803, in Event Viewer, there are between two and four Audit Failures for something related to Cryptography.  So my Win 10 machine is insecure?  I have run sfc /scannow  and  Dism /Online /Cleanup-Image /RestoreHealth many times, with no luck.  And I hardly even use my Win 10 machine - there are almost no apps on it yet.  My actual Win 10 build is 17134.706

Here are the latest five Cryptography-related Audit Failures, from two reboots:

LATEST OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 12:27:52 PM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        DESKTOP-3#####N[My user name]

    Account Name:        [My user name]

    Account Domain:        DESKTOP-3#####N

    Logon ID:        0x3EC24

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    Microsoft Connected Devices Platform device certificate

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T16:27:52.339705400Z" />

    <EventRecordID>19582</EventRecordID>

    <Correlation />

    <Execution ProcessID="880" ThreadID="948" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-21-[My Identifier 10-9-10 digits]-1001</Data>

    <Data Name="SubjectUserName">[My user name]</Data>

    <Data Name="SubjectDomainName">DESKTOP-3#####N</Data>

    <Data Name="SubjectLogonId">0x3ec24</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">Microsoft Connected Devices Platform device certificate</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

FOURTH OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 12:26:51 PM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        LOCAL SERVICE

    Account Name:        LOCAL SERVICE

    Account Domain:        NT AUTHORITY

    Logon ID:        0x3E5

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    [Hex number]

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T16:26:51.704606400Z" />

    <EventRecordID>19552</EventRecordID>

    <Correlation />

    <Execution ProcessID="880" ThreadID="1004" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-19</Data>

    <Data Name="SubjectUserName">LOCAL SERVICE</Data>

    <Data Name="SubjectDomainName">NT AUTHORITY</Data>

    <Data Name="SubjectLogonId">0x3e5</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">[Hex number]</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

THIRD OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 11:29:28 AM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        DESKTOP-3#####N[My user name]

    Account Name:        [My user name]

    Account Domain:    DESKTOP-3#####N

    Logon ID:        0x3EF94

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    Microsoft Connected Devices Platform device certificate

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T15:29:28.196237300Z" />

    <EventRecordID>19387</EventRecordID>

    <Correlation />

    <Execution ProcessID="884" ThreadID="928" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-21-[My Identifier 10-9-10 digits]-1001</Data>

    <Data Name="SubjectUserName">[My user name]</Data>

    <Data Name="SubjectDomainName">DESKTOP-3#####N</Data>

    <Data Name="SubjectLogonId">0x3ef94</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">Microsoft Connected Devices Platform device certificate</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

SECOND OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 11:28:27 AM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        LOCAL SERVICE

    Account Name:        LOCAL SERVICE

    Account Domain:        NT AUTHORITY

    Logon ID:        0x3E5

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    [Hex number]

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T15:28:27.709849300Z" />

    <EventRecordID>19363</EventRecordID>

    <Correlation />

    <Execution ProcessID="884" ThreadID="992" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-19</Data>

    <Data Name="SubjectUserName">LOCAL SERVICE</Data>

    <Data Name="SubjectDomainName">NT AUTHORITY</Data>

    <Data Name="SubjectLogonId">0x3e5</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">[Hex number]</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

FIRST OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 11:28:27 AM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        LOCAL SERVICE

    Account Name:        LOCAL SERVICE

    Account Domain:        NT AUTHORITY

    Logon ID:        0x3E5

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    [Hex number]

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T15:28:27.709849300Z" />

    <EventRecordID>19363</EventRecordID>

    <Correlation />

    <Execution ProcessID="884" ThreadID="992" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-19</Data>

    <Data Name="SubjectUserName">LOCAL SERVICE</Data>

    <Data Name="SubjectDomainName">NT AUTHORITY</Data>

    <Data Name="SubjectLogonId">0x3e5</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">[Hex number]</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

So, what the *** are these, and how do we fix?  No guesses - just the real fix.


glnzglnz

☺ In the office, Dell Optiplex 7040 with 8GB RAM, Win 7 Pro 64-bit and Office 2010

☻ At home, Dell Optiplex 7010 with 16GB RAM dual-booting Win 7 Pro 64-bit (now with Office 365 Home) and Win 10 Pro 64-bit

♥ Also still have Dell Optiplex 755 with 4GB RAM with Win XP Pro SP3 (which still gets updates with the POS hack) and Office 2003

Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

48 answers

Sort by: Most helpful
  1. Anonymous
    2019-05-12T18:39:22+00:00

    Larry - A few follow-up Qs and some answers to your Qs:

    1. What Event Viewer category lets me see all Audit Successes and Audit Failures together in a single Event Viewer list?  That way I can see more easily if the particular Failures are followed by Successes for the same parameters (assuming the PC retries)?
    2. I have not yet run your scripts from the very long thread on google forum (which is now very hard to use because I could not find an "Expand All" button and your internal links don't work anymore).  However, I did download SetACL.exe.  Four sub-Qs - and FYI my Win 10 is Pro 64-bit version 1803:
      1. I recall from the long Google thread that the SetACL.exe (the file itself) has to be in the correct folder so that your scripts can find it.  Which folder is that?  The same folder as your scripts?
      2. Since my OS is 64-bit, should I put the 64-bit version of SetACL,exe in that folder or the 32-bit version - or maybe both versions (but then they could not have the same file name)?
      3. Instead of putting SetACL.exe in that folder, would it work if I dropped in a shortcut like SetACL-shortcut.lnk that pointed to a different folder where SetACL.exe is actually sitting?
      4. What else do I have to know about SetACL.exe to make your scripts work?
    3. Sorry, given how long that google forum thread is (and no longer expandable), could you Reply here again with the links to your script(s) and anywhere (besides the google forum) where you posted instructions?
    4. You asked "Is your failing Key Name hex# always the same?"

    First, the Key Name is EITHER a 16-digit hex number (base 16, from 0 to f) with no hyphens or spaces OR the phrase "Microsoft Connected Devices Platform device certificate".

    Second, when it's a number, it is always the same number. 5. You asked, "Is it a hex# or a GUID like {EE1317A2-D183-4A42-9CA7-293B11E51FA0}?"

    The number is a 16-digit hex # without hyphens or spaces and NOT in GUID style. 6. You wrote, "If it's the same hex string, you may be able to trackdown the source from the string."
    Sorry - how do I do that?  Just a regedit Find search for that 16-digit number?  What am I looking for? 1. FYI - I have just finished a regedit search now and found that hex number as the entry for the following:

    • HKEY_CURRENT_USER\Software\Microsoft\IdentityCRL\UserExtendedProperties[MyName]@outlook.com\cid
    • HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Accounts\Personal\cid

       -- and \UserCID

       -- and this over-key HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Accounts\Personal also has subkeys for

            (a) UserEmail which is "[MyName]@outlook.com" and

            (b) UserFolder, which is "C:\Users[MyName]\OneDrive"

    • HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Claims\Claim[HexNumber] in which the data is a long GUID-style number
    • HKEY_CURRENT_USER\Software\SyncEngines\Providers\OneDrive\Personal\CID

       -- and this over-key HKEY_CURRENT_USER\Software\SyncEngines\Providers\OneDrive\Personal also has sub-keys for

             (a) MountPoint, in which the data is "C:\Users[MyName]\OneDrive", and

             (b) UrlNamespace, in which the data is "https://d.docs.live.net"

    • HKEY_USERS\S-1-5-21-[My Identifier 10-9-10 digits]-1001\Software\Microsoft\IdentityCRL\UserExtendedProperties[MyName]@outlook.com\cid
    • HKEY_USERS\S-1-5-21-[My Identifier 10-9-10 digits]-1001\Software\Microsoft\OneDrive\Accounts\Personal\cid

       -- and \UserCID

       -- and this over-key - HKEY_USERS\S-1-5-21-[My Identifier 10-9-10 digits]-1001\Software\Microsoft\OneDrive\Accounts\Personal\ also has subkeys for

            (a) UserEmail which is "[MyName]@outlook.com" and

            (b) UserFolder, which is "C:\Users[MyName]\OneDrive"

    • HKEY_USERS\S-1-5-21-[My Identifier 10-9-10 digits]-1001\Software\Microsoft\OneDrive\Claims\Claim[HexNumber] in which the data is a long GUID-style number
    • HKEY_USERS\S-1-5-21-[My Identifier 10-9-10 digits]-1001\Software\SyncEngines\Providers\OneDrive\Personal\CID

       -- and this over-key HKEY_USERS\S-1-5-21-[My Identifier 10-9-10 digits]-1001\Software\SyncEngines\Providers\OneDrive\Personal\ also has sub-keys for

             (a) MountPoint, in which the data is "C:\Users[MyName]\OneDrive", and

             (b) UrlNamespace, in which the data is "https://d.docs.live.net" 7. You asked, "Is the key name hex# the connection to one-drive?"

    See long answer above.

    Whew - Hope this has some interesting clues to the Audit Failure problem. 

    And please remember that although I give here a lot of info about the Key Name: [Hex number}, some times the Key Name is "Microsoft Connected Devices Platform device certificate".

    THANKS !!!

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2019-05-12T18:33:27+00:00

    See my next Reply -

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2019-05-12T01:27:17+00:00

    There are others with the problem. There is a post I replied to around a year ago on this forum with the OP saying he had the same problem. I read some time ago that if you do a clean install of windows the problem won't exist. Don't know if that solution works or not. I keep telling myself I will do a clean install but I take care of my elderly Mom who has dementia and just can't seem to find the time anymore and since I don't seem to be having problems I just don't want to try to find the time.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2019-05-12T00:17:41+00:00

    Hey Larry - you've been great - many thanks.

    I'll be taking another look the next few days.  And you are correct that it is ROOT, as in "Groot".

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2019-05-11T23:50:51+00:00

    Glnz: Re: Boot 5061 Audit failures:

    I looked at my Security events.  I too have 5061 Audit Failures, although the 5061 Audits are >90% successful.  The few failures seem to:

      -occur on boot

      -after 2 each successful User and Local Service/NT Auth audits

        i.e. the 5th 5061 audit fails.

      -fail only for my user account (no Local Sevice failures)

    The successful ones always have Algorithm: ECDSA_P256;

    The failing one is always: Unknown.

    Each of the successful ones is for a different Key Name.  Sometimes the keyname is a hex string, but usually its:

      Microsoft Connected Devices Platform device certificate

    including my (5th) user account failure.

    Is your failing Key Name hex# always the same?

    Is it a hex# or a GUID like {EE1317A2-D183-4A42-9CA7-293B11E51FA0}?

    If it's the same hex string, you may be able to trackdown the source from the string.  

    Is the key name hex# the connection to one-drive?

    My guess is that when the audit runs, it doesn't specify an Algorithm, which always fails.  This false negative audit may have been introduced with 1803, or maybe the Unknown audit was alway there, but the code got tighter in 1803.

    Was this answer helpful?

    0 comments No comments