Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit

Anonymous
2019-04-28T20:45:27+00:00

Immediately after every reboot of Win 10 Pro 64-bit version 1803, in Event Viewer, there are between two and four Audit Failures for something related to Cryptography.  So my Win 10 machine is insecure?  I have run sfc /scannow  and  Dism /Online /Cleanup-Image /RestoreHealth many times, with no luck.  And I hardly even use my Win 10 machine - there are almost no apps on it yet.  My actual Win 10 build is 17134.706

Here are the latest five Cryptography-related Audit Failures, from two reboots:

LATEST OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 12:27:52 PM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        DESKTOP-3#####N[My user name]

    Account Name:        [My user name]

    Account Domain:        DESKTOP-3#####N

    Logon ID:        0x3EC24

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    Microsoft Connected Devices Platform device certificate

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T16:27:52.339705400Z" />

    <EventRecordID>19582</EventRecordID>

    <Correlation />

    <Execution ProcessID="880" ThreadID="948" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-21-[My Identifier 10-9-10 digits]-1001</Data>

    <Data Name="SubjectUserName">[My user name]</Data>

    <Data Name="SubjectDomainName">DESKTOP-3#####N</Data>

    <Data Name="SubjectLogonId">0x3ec24</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">Microsoft Connected Devices Platform device certificate</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

FOURTH OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 12:26:51 PM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        LOCAL SERVICE

    Account Name:        LOCAL SERVICE

    Account Domain:        NT AUTHORITY

    Logon ID:        0x3E5

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    [Hex number]

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T16:26:51.704606400Z" />

    <EventRecordID>19552</EventRecordID>

    <Correlation />

    <Execution ProcessID="880" ThreadID="1004" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-19</Data>

    <Data Name="SubjectUserName">LOCAL SERVICE</Data>

    <Data Name="SubjectDomainName">NT AUTHORITY</Data>

    <Data Name="SubjectLogonId">0x3e5</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">[Hex number]</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

THIRD OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 11:29:28 AM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        DESKTOP-3#####N[My user name]

    Account Name:        [My user name]

    Account Domain:    DESKTOP-3#####N

    Logon ID:        0x3EF94

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    Microsoft Connected Devices Platform device certificate

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T15:29:28.196237300Z" />

    <EventRecordID>19387</EventRecordID>

    <Correlation />

    <Execution ProcessID="884" ThreadID="928" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-21-[My Identifier 10-9-10 digits]-1001</Data>

    <Data Name="SubjectUserName">[My user name]</Data>

    <Data Name="SubjectDomainName">DESKTOP-3#####N</Data>

    <Data Name="SubjectLogonId">0x3ef94</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">Microsoft Connected Devices Platform device certificate</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

SECOND OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 11:28:27 AM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        LOCAL SERVICE

    Account Name:        LOCAL SERVICE

    Account Domain:        NT AUTHORITY

    Logon ID:        0x3E5

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    [Hex number]

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T15:28:27.709849300Z" />

    <EventRecordID>19363</EventRecordID>

    <Correlation />

    <Execution ProcessID="884" ThreadID="992" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-19</Data>

    <Data Name="SubjectUserName">LOCAL SERVICE</Data>

    <Data Name="SubjectDomainName">NT AUTHORITY</Data>

    <Data Name="SubjectLogonId">0x3e5</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">[Hex number]</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

FIRST OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 11:28:27 AM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        LOCAL SERVICE

    Account Name:        LOCAL SERVICE

    Account Domain:        NT AUTHORITY

    Logon ID:        0x3E5

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    [Hex number]

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T15:28:27.709849300Z" />

    <EventRecordID>19363</EventRecordID>

    <Correlation />

    <Execution ProcessID="884" ThreadID="992" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-19</Data>

    <Data Name="SubjectUserName">LOCAL SERVICE</Data>

    <Data Name="SubjectDomainName">NT AUTHORITY</Data>

    <Data Name="SubjectLogonId">0x3e5</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">[Hex number]</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

So, what the *** are these, and how do we fix?  No guesses - just the real fix.


glnzglnz

☺ In the office, Dell Optiplex 7040 with 8GB RAM, Win 7 Pro 64-bit and Office 2010

☻ At home, Dell Optiplex 7010 with 16GB RAM dual-booting Win 7 Pro 64-bit (now with Office 365 Home) and Win 10 Pro 64-bit

♥ Also still have Dell Optiplex 755 with 4GB RAM with Win XP Pro SP3 (which still gets updates with the POS hack) and Office 2003

Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

48 answers

Sort by: Most helpful
  1. Anonymous
    2019-05-18T00:24:52+00:00

    I also had started to set up outlook online mail for email and did not finish,(decided the desktop email program was fine for my needs and I was not sure how to set it up). Looks like there could be a connection on audit failures for Microsoft online office outlook mail per your post. I am uncomfortable with working in the registry and have decided to clean install the next upgrade (1903) when the bugs are worked out of that. (little laugh, as there are some very old problems in windows that date back to windows 7 and before that will never be addressed, event ID10016 for example).Too old of code mixed in with the new. Do you think possibly sync is some of the problem?

    Thanks for all your hard work and information.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2019-05-17T23:35:16+00:00

    Larry and Coni - I take it my long post four above doesn't provide the final clues?

    Thanks for checking and posting here.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2019-05-17T23:27:07+00:00

    Larry,

    I disabled onedrive from the onedrive properties that resided in the system tray. I found an article on how to turn it off and disable although I did not uninstall it. the instructions I used are here.

    https://support.office.com/en-us/article/turn-off-disable-or-uninstall-onedrive-f32a17ce-3336-40fe-9c38-6efb09f944b0?ui=en-US&rs=en-US&ad=US

    Something interesting. The other day I uninstalled PC Manager for my Matebook X pro ( the laptop updater program) and now I have only 2 audit failures instead of 3 at boot. It makes me wonder if these audit failures are phone home programs that are trying to connect at boot up. It did drop one of the audit failures. 

    Another thing that comes to  mind about connected devices is I do not let any of my lpatops communicate with one another but one day I realized my chromebooks  bluetooth  had enabled without my knowledge and I think the nearfield communication was trying to connect to my windows laptop , I turned off Bluetooth but did notice an audit failure that involved chrome which I do not use on my windows laptop.  This is probably just a harebrained idea.

     I think when 1903 comes out and any bugs ( which I am sure it will have) get ironed out by updates, I will clean install it (format and all) to see if I lose the audit failures I have remaining. I do ot think they will go away with the upgrade alone.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2019-05-17T22:40:51+00:00

    Coni:

    Did the CryptSvc problem stop after disabling one-drive?

    How did you disable one-drive?

    Thx for the event-viewer tips.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2019-05-12T20:20:44+00:00

    I Edited this post.

    It does seem the problem may reside with one drive. I did used to use one drive and then stopped it and disabled it. Here is how to create custom view.

    https://www.thewindowsclub.com/create-custom-views-in-event-viewer-on-windows-10

    If you cannot do it cause things are greyed out, here are solutions.

    https://www.tenforums.com/performance-maintenance/121816-event-viewer-laptop-unable-create-custom-view.html

    Or

    https://www.tenforums.com/windows-updates-activation/111890-event-viewer-create-custom-view-drop-down-gone-w-clean-1803-home.html

    Was this answer helpful?

    0 comments No comments