srv2.sys

Associated Error Codes

Below lists error codes and symbolic names found for this module.

CodeFound inDescription
0x100000351011Audit Failure
0x300000001011Info
0x300000011011Start
0x300000021011Stop
0x300000091011Send
0x500000021011Error
0x500000031011Warning
0x500000041011Information
0x900000011011Microsoft-Windows-SMBServer/Performance
0x900000021011Microsoft-Windows-SMBServer/Analytic
0x900000031011Microsoft-Windows-SMBServer/Operational
0x900000041011Microsoft-Windows-SMBServer/Diagnostic
0x900000051011Microsoft-Windows-SMBServer/Security
0x900000061011Microsoft-Windows-SMBServer/Connectivity
0x900000071011Microsoft-Windows-SMBServer/Audit
0xb00000c81011SMB2 Work Item Component Transition
0xb00000c91011SMB2 Work Item allocated
0xb00000ca1011SMB2 Work Item released
0xb00000cb1011SMB2 Work Item activity id transfer
0xb00000cc1011SMB2 Work Item external activity id stop
0xb00001f41011SMB2 Connection accepted
0xb00001f51011SMB2 Connection Disconnected by Peer
0xb00001f61011SMB2 Connection Terminated
0xb00002261011SMB2 Session Allocated
0xb00002271011Smb Session Authentication Failure
0xb00002281011SMB2 Session Authentication Success
0xb00002291011SMB2 Session Bound to Connection
0xb000022a1011SMB2 Session Terminated
0xb000022b1011SMB2 Session Closed.
0xb00002581011SMB2 TreeConnect Allocated
0xb00002591011SMB2 TreeConnect Disconnected
0xb000025a1011SMB2 TreeConnect Terminated
0xb000025b1011SMB2 TreeConnect Failed due to Cluster Endpoint Initializing
0xb000028a1011SMB2 Open established
0xb000028b1011SMB2 Open Disconnected - Preserved
0xb000028c1011SMB2 Open Reconnected
0xb000028d1011SMB2 Open Suspended - Preserved
0xb000028e1011SMB2 Open Closed
0xb000028f1011SMB2 Open Timed Out
0xb00002901011SMB2 Open Terminated
0xb00002911011SMB2 Open Clustered Client Failover Closed
0xb00002921011File handle for file "%8\%2" was invalidated by user %4 from computer %6
0xb00002bc1011SMB2 Share Added
0xb00002bd1011SMB2 Share Modified
0xb00002be1011SMB2 Share Deleted
0xb00003e81011S4U2Self authentication failure - The client could not be reauthenticated with S4U2Self to obtain claims. This may be expected if the account is not a domain account.
0xb00003e91011SRV Disabled - The SMB1 negotiate request fails due to SMB1 is disabled.
0xb00003ea1011RKF failure - SRV2 failed to get acknowledgement from Resume Key filter for persistent handle request.
0xb00003eb10The server received an unencrypted message from client %4. Message was rejected. Guidance: This event indicates that a client is sending unencrypted data even though the SMB share requires encryption.
0xb00003ec10The server received an incorrectly signed message from client %2. Message was rejected. Guidance: This event indicates that a client is sending an incorrectly signed request.
0xb00003ed1011The server failed to validate negotiation from client %2. Connection was terminated.
0xb00003ee1011The share denied access to the client. Client Name: %10 Client Address: %6 User Name: %8 Session ID: %17 Share Name: %2 Share Path: %4 Status: %16 (%15) Mapped Access: %11 Granted Access: %12 Security Descriptor: %14 Guidance: You should expect access denied errors when a principal accesses a share without the necessary permissions. Usually, this indicates that the principal does not have direct security permissions or lacks membership in a group that has direct access permissions. To determine and correct the permissions on the specified share, an administrator can use the Security tab in File Explorer Properties dialog, the SMBSHARE Windows PowerShell module, or the NET SHARE command. You can also use the Effective Access tab in File Explorer to help diagnose the issue. Applications may generate access denied errors if they attempt to open files in a writable mode first, and then reopen the files in a read-only mode. In this case, no user action is required. If access to the share is denied and this event is not logged, you can examine the file and folder NTFS/REFS permissions. This error does not indicate a problem with authentication, only authorization.
0xb00003ef1011The share denied anonymous access to the client. Client Name: %8 Client Address: %6 Share Name: %2 Share Path: %4 Guidance: You should expect this error when a client attempts to connect to shares and does not provide any credentials. This indicates that the client is not providing a user name (and domain credentials, if necessary). By default, anonymous access to shares is denied. This error does not always indicate a problem with authorization, but mainly authentication. It is more common with non-Windows clients.
0xb00003f11011The server denied anonymous access to the client. Client Name: %4 Client Address: %2 Session ID: %5 Guidance: You should expect this error when a client attempts to connect to shares and does not provide any credentials. This indicates that the client is not providing a user name (and domain credentials, if necessary). By default, Windows Server denies anonymous access to shares. This error does not always indicate a problem with authorization, but mainly authentication. It is more common with non-Windows clients.
0xb00003f21011Endpoint added. Name: %2 Domain Name: %4 Transport Name: %6 Transport Flags: %7 Guidance: You should expect this event when the server starts listening on an interface, such as during system restart or when enabling a network adaptor. No user action is required.
0xb00003f31011Endpoint removed. Name: %2 Domain Name: %4 Transport Name: %6 Guidance: You should expect this event when the server stops listening on an interface, such as during shutdown or when disabling a network adaptor. No user action is required.
0xb00003f41011The network name information changed. Change Type: %1 Net Name: %3 IP Address: %9 Flags: %4 Interface Index: %5 Capability: %6 Link Speed: %7 Guidance: You should expect this event on a Windows Failover Cluster node during failover operations, at system startup, or during network configuration. No user action is required.
0xb00003f51011Endpoint coming online. Endpoint Name: %2 Transport Name: %4 Guidance: You should expect this event on a Windows Failover Cluster node during failover operations. No user action is required.
0xb00003f61011Endpoint going offline. Endpoint Name: %2 Transport Name: %4 Guidance: You should expect this event on a Windows Failover Cluster node during failover operations. No user action is required.
0xb00003f71011Decrypt call failed. Client Name: %2 Client Address: %4 Session ID: %7 Status: %6 (%5) Guidance: This event commonly occurs because a previous SMB session no longer exists. It may also be caused by packets that are altered on the network between the computers due to either errors or a "man-in-the-middle" attack.
0xb00003f81011Reopen failed. Client Name: %7 Client Address: %9 User Name: %13 Session ID: %14 Share Name: %11 File Name: %16 Resume Key: %20 Status: %2 (%1) RKF Status: %4 (%3) Durable: %17 Resilient: %18 Persistent: %19 Reason: %21 Guidance: The client attempted to reopen a continuously available handle, but the attempt failed. This typically indicates a problem with the network or underlying file being re-opened.
0xb00003f91011Handle scavenged. Share Name: %7 File Name: %9 Resume Key: %5 Persistent File ID: %3 Volatile File ID: %4 Durable: %1 Resilient or Persistent: %2 Guidance: The server closed a handle that was previously reserved for a client after 60 seconds. You should expect this event on a computer that is continuously available where a client did not gracefully close its session. For instance, this may occur when the client unexpectedly restarted.
0xb00003fa1011Backchannel invalidation of session completed. Session ID: %1 Status: %3 (%2) Task Status: %5 (%4) Guidance: You should expect this event on a computer that is continuously available. No user action is required
0xb00003fb1011Backchannel invalidation of file completed. Resume Key: %1 Status: %3 (%2) Task Status: %5 (%4) Guidance: You should expect this event on a computer that is continuously available. No user action is required
0xb00003fc1011File system operation has taken longer than expected. Client Name: %8 Client Address: %10 User Name: %6 Session ID: %3 Share Name: %12 File Name: %14 Command: %1 Duration (in milliseconds): %15 Warning Threshold (in milliseconds): %16 Guidance: The underlying file system has taken too long to respond to an operation. This typically indicates a problem with the storage and not SMB.
0xb00003fd1011LmCompatibilityLevel value is different from the default. Configured LM Compatibility Level: %1 Default LM Compatibility Level: %2 Guidance: LAN Manager (LM) authentication is the protocol used to authenticate Windows clients for network operations. This includes joining a domain, accessing network resources, and authenticating users or computers. This determines which challenge/response authentication protocol is negotiated between the client and the server computers. Specifically, the LM authentication level determines which authentication protocols the client will try to negotiate or the server will accept. The value set for LmCompatibilityLevel determines which challenge/response authentication protocol is used for network logons. This value affects the level of authentication protocol that clients use, the level of session security negotiated, and the level of authentication accepted by servers. Value (Setting) - Description 0 (Send LM & NTLM responses) - Clients use LM and NTLM authentication and never use NTLMv2 session security. Domain controllers accept LM, NTLM, and NTLMv2 authentication. 1 (Send LM & NTLM - use NTLMv2 session security if negotiated) - Clients use LM and NTLM authentication, and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication. 2 (Send NTLM response only) - Clients use NTLM authentication only and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication. 3 (Send NTLM v2 response only) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication. 4 (Send NTLMv2 response only/refuse LM) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers refuse LM and accept only NTLM and NTLMv2 authentication. 5 (Send NTLM v2 response only/refuse LM & NTLM) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers refuse LM and NTLM and accept only NTLMv2 authentication. Incompatibly configured LmCompatibility levels between a client and server (such as 0 on a client and 5 on a server) prevent access to the server. Non-Microsoft clients and servers also provide these configuration settings.
0xb00003fe1011File and printer sharing firewall rule enabled. Guidance: You should expect this event when Windows Firewall is configured to enable the File and Printer Sharing rule, which allows inbound SMB traffic. This event occurs on a computer that has custom shares configured.
0xb00003ff1011One or more shares present on this server have access based enumeration enabled. Guidance: You should expect this event when enabling access-based enumeration on one or more shares by using either Server Manager or the Set-SmbShare Windows PowerShell cmdlet. Access-based enumeration can raise CPU utilization when clients connect to shares with folders containing many peer-level resources to which a user does not have access. You can control the CPU utilization by configuring the ABELevel value in the Windows registry: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanServer\Parameters\ABELevel [DWORD] You can set the value for ABELevel to greater depths to minimize CPU overhead, but doing so diminishes the effectiveness of access-based enumeration: Value = 0: access-based enumeration is enabled for all levels Value = 1: access-based enumeration is enabled for a depth of 1 (example: \server\share) Value = 2: access-based enumeration is enabled for a depth of 2 (example: \server\share\folder) You can continue setting values for multiple depth levels.
0xb00004001011SMB2 and SMB3 have been disabled on this server. This results in reduced functionality and performance. Registry Key: HKLM\System\CurrentControlSet\Services\LanmanServer\Parameters Registry Value: Smb2 Default Value: 1 (or not present) Current Value: 0 Guidance: You should expect this event when disabling SMB2/SMB3. Microsoft does not recommend disabling SMB2/SMB3. When SMB3 is disabled, you cannot use features such as SMB Transparent Failover, SMB Scale Out, SMB Multichannel, SMB Direct (RDMA), SMB Encryption, VSS for SMB file shares, and SMB Directory Leasing. In most scenarios, SMB provides a troubleshooting workaround as an alternative to disabling SMB2/SMB3. Use the Set-SmbServerConfiguration Windows PowerShell cmdlet to enable SMB2/SMB3.
0xb00004011011One or more named pipes or shares have been marked for access by anonymous users. This increases the security risk of the computer by allowing unauthenticated users to connect to this server. Registry Key: HKLM\System\CurrentControlSet\Services\LanmanServer\Parameters Registry Values: NullSessionPipes, NullSessionShares Default Value: Empty (or not present) Current Value: Non-empty Guidance: You should expect this event when modifying the default values of NullSessionShares and NullSessionPipes. On a typical file server, these settings do not exist or do not contain values, which is the most secure configuration. By default, domain controllers populate the NullSessionShares entry with netlogon, samr, and lsarpc to allow legacy access methods.
0xb00004021011File leasing has been disabled for the SMB2 and SMB3 protocols. This reduces functionality and can decrease performance. Registry Key: HKLM\System\CurrentControlSet\Services\LanmanServer\Parameters Registry Value: DisableLeasing Default Value: 0 (or not present) Current Value: non-zero Guidance: You should expect this event when disabling SMB 3 Leasing. Microsoft does not recommend disabling SMB Leasing. Once disabled, traffic from client to server may increase since metadata and data may no longer be retrieved from a local cache.
0xb00004031011The file and printer sharing firewall ports are currently closed. This is the default configuration for a system that is not sharing content or is on a Public network. Guidance: You should expect this event when Windows Firewall is not configured to enable the File and Printer Sharing rule, which allows inbound SMB traffic. This event occurs on a computer that does not have custom shares configured. Clients cannot access SMB shares on this computer until SMB traffic is allowed through the firewall.
0xb00004041011The maximum cluster-supported SMB dialect has changed. NewMaxDialect: %1 OldMaxDialect: %2 Guidance: You should expect this event during a Windows Failover Cluster upgrade. No user action is required.
0xb00004051011The Cipher Suite Order group policy setting is invalid. Guidance: This event indicates that an administrator has configured an invalid value for the "Computer Configuration\Administrative Templates\Network\Lanman Server\Cipher Suite Order" group policy setting. The server will use the default cipher suite order "%1" until this error is resolved.
0xb00004061011An MDL read or write completion request failed. Server Name: %2 Share Name: %4 File Name: %6 IsRead: %7 Status: %8 Guidance: The SMB server sends MDL completion requests to a file system upon completion of a buffered I/O to release system resources. The file system and its filter drivers must not fail MDL completion requests. Failures may result in memory leaks and degraded system performance and stability. Non-Microsoft file system filter drivers are the most common cause of failed MDL completion requests.
0xb00004071011The server detected a problem and has captured a live kernel dump to collect debug information. Reason: %1 Dump Location: %SystemRoot%\LiveKernelReports Guidance: The server supports the Live Dump feature, where the detection of a problem results in a kernel memory dump, but no bugcheck and reboot. This allows Microsoft Support to examine memory dumps without requiring a reboot or manual intervention. The reason code indicates the type of problem that was detected. Stalled I/O An I/O is taking an unreasonably long time to complete. Malfunctioning third-party file system minifilter drivers are a common source of this problem. Other causes include failed disks or a client-driven I/O workload that greatly exceeds the server's capacity.
0xb00004081011The server detected a problem but was unable to capture a live kernel dump to collect debug information. Reason: %1 Guidance: The server supports the Live Dump feature, where the detection of a problem results in a kernel memory dump, but no bugcheck and reboot. This allows Microsoft Support to examine memory dumps without requiring a reboot or manual intervention. The reason code indicates the type of problem that was detected. In this case, the server's request to create a live kernel dump was rejected. This is usually due to the live kernel dump throttle, which prevents frequent dumps from consuming too much disk space. Either wait for the throttle limit to expire (by default, 7 days), or contact Microsoft Support for steps to override the throttle. This event is written to the log no more than once per day. The problem that caused the server to the request a live kernel dump may be occuring more frequently. Stalled I/O An I/O is taking an unreasonably long time to complete. Malfunctioning third-party file system minifilter drivers are a common source of this problem. Other causes include failed disks or a client-driven I/O workload that greatly exceeds the server's capacity.
0xb00004091011Sent RDMA %1 event to LanmanServer for interface %3.
0xb000040a1011Send RDMA Endpoint notification failure - %1
0xb000040b1011RDMA Endpoint %4 for interface %2 was %1.
0xb000040c1011RDMA Endpoint allocation failure - Endpoint allocation failed for interface %1. %2
0xb000040d1011RDMA listener creation failure - %1
0xb000040e1011RDMA Send endpoint notification RPC failure for device %3 - %1
0xb000040f1011Received Nsi notification type %1 for interface %2 with NdkOperationalState %3
0xb00004101011Received Mib notification type %1 for interface %2
0xb00004111011Error reading FSCTL properties information from the registry. Registry value entry %3 will be ignored. Error: %1
0xb00004121011The certificate for the server is about to expire. Subject: %2 Thumbprint: %4 Expires on %5. Guidance: This event indicates the certificate is about to expire. Renew or issue new certificates to avoid service interruption.
0xb00004131011RDMA connection disconnected. Transport name: %3 Milliseconds spent closing the connection: %1 Guidance: Closing an RDMA connection should not take longer than 2 minutes. An RDMA IO that takes an abnormally long time to complete indicates a problem with the RDMA network adapters on this computer or its remote host. Contact your RDMA vendor for an updated driver and further troubleshooting.
0xb000041410Quic connection shutdown. Error: %1 Reason: %2 Endpoint Name: %4 Transport Name: %6 Guidance: This event indicates that the winquic connection is shuting down by the server. This event commonly occurs because the server certificate mapping is not created. It may also be caused by the server failed to configure the winquic connections.
0xb00004151011The server failed to update server certificate mapping. Name: %2 Subject: %4 Thumbprint: %6 The certificate can't be used for the server due to error %7 The server certificate mapping %9 removed.
0xb00007081011CA failure - Failed to set continuously available property on a new or existing file share as the file share is not a cluster share.
0xb00007091011CA failure - Failed to set continuously available property on a new or existing file share as Resume Key filter is not started or has failed to attach to the underlying volume.
0xb000070a1011The server failed to reserve the next ID region in the cluster registry.
0xb000070b1011The security descriptor differs from the default value. Path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\DefaultSecurity\%1 Guidance: This is typically caused by an administrator or a third party changing the security on the object manually. To reset the security back to the default value, delete the path shown above. Microsoft does not recommend changing the default security of %1 as it may cause application incompatibilities or security concerns.
0xb000076c1011TDI mode enabled: %1
0xb000076d1011Failed to allocate an NSI table for network interface enumeration: %1
0xb000076e1011Received notification of a newly-started network interface with Luid %2 on address family %1 (IPv4 == 2, IPv6 == 23)
0xb000076f1011Received notification of a stopped network interface with Luid %2 on address family %1 (IPv4 == 2, IPv6 == 23)
0xb00007701011Failed to open network interface with Luid %1: error %2
0xb00007711011The server closed the session as part of periodic system cleanup. Session Id: %1 Instance Id: %2 Reason: %3
0xb00007d01011Packet Fragment (%2 bytes)
0xb0000bb81011SMB1 access Client Address: %1 Guidance: This event indicates that a client attempted to access the server using SMB1. To stop auditing SMB1 access, use the Windows PowerShell cmdlet Set-SmbServerConfiguration.
0xb0000bcd1011The SMB server observed that the client doesn't support signing. Client name: %2 Server requires signing: %3
0xb0000bd01011The SMB server observed that the client did not send an SPN during authentication, indicating that the client does not support Extended Protection for Authentication (EPA) or that support for EPA is disabled. Client name: %2 SPN Query Status: %3 SPN Validation Policy: %4
0xb0000bd11011The SMB server observed that the client sent an unrecognized SPN during authentication. Client name: %2 SPN: %3 SPN Validation Policy: %6
0xb0000bd21011The SMB server observed that the client sent an empty SPN during authentication, which indicates the client is capable of sending an SPN but elected not to supply one. Client name: %2 SPN Validation Policy: %3
0xb0000bd31011The SMBv1 server observed that the SMBv1 client does not have signing enabled. Client name: %2 Server requires signing: %3 Guidance: This event indicates that the SMBv1 client may not support SMB signing, but due to protocol limitations, this cannot be determined with certainty. Further evaluation is recommended to verify the client's signing capabilities. Prior to Windows Vista, SMBv1 clients that did not have signing explicitly enabled could not perform SMB signing. This behavior was changed with the release of Windows Vista and was also backported to Windows XP and Windows Server 2003 through updates. With these changes, SMB clients may support signing even if it is not explicitly enabled, provided the server requires it.
0xb0009c401011Packet (%4 bytes)
0xb00102271011SMB Session Authentication Failure Client Name: %11 Client Address: %6 User Name: %9 Session ID: %7 Status: %4 (%3) Guidance: You should expect this error when attempting to connect to shares using incorrect credentials. This error does not always indicate a problem with authorization, but mainly authentication. It is more common with non-Windows clients. This error can occur when using incorrect usernames and passwords with NTLM, mismatched LmCompatibility settings between client and server, duplicate Kerberos service principal names, incorrect Kerberos ticket-granting service tickets, or Guest accounts without Guest access enabled
0xb00103e91011A client attempted to access the server using SMB1 and was rejected because SMB1 file sharing support is disabled or has been uninstalled. Guidance: An administrator has disabled or uninstalled server support for SMB1. Clients running Windows XP / Windows Server 2003 R2 and earlier will not be able to access this server. Clients running Windows Vista / Windows Server 2008 and later no longer require SMB1. To determine which clients are attempting to access this server using SMB1, use the Windows PowerShell cmdlet Set-SmbServerConfiguration to enable SMB1 access auditing.
0xb00103eb1011The server received an unencrypted message from client when encryption was required. Message was rejected. Client Name: %4 Client Address: %8 User Name: %6 Session ID: %9 Share Name: %2 Guidance: This event indicates that a client is sending unencrypted data even though the SMB share requires encryption.
0xb00103ec1011The server rejected an incorrectly signed message. Client Name: %2 Client Address: %6 User Name: %4 Session ID: %7 Guidance: This event indicates that a client is sending an incorrectly signed request.
0xb00103ed1011The server rejected an invalid negotiation request. Connection was terminated. Client Name: %2 Client Address: %6 User Name: %4 Session ID: %13 Expected Dialect: %7 Expected Capabilities: %8 Expected Security Mode: %9 Received Dialect: %10 Received Capabilities: %11 Received Security Mode: %12 Guidance: This event indicates that a client is attempting to negotiate a second connection using a mismatched dialect or capabilities.
0xb001070c1011No SMB1 usage detected in the last 20 minutes. Guidance: This event indicates that no attempt was made to contact this computer via the SMB1 protocol. After %1 online days of no SMB1 contact attempts, the SMB1 Server service will automatically uninstall.
0xb0010bba1011A remote device attempted SMB1 connection to this computer. Client Address: %1 Guidance: This event indicates that a client attempted to access the server using SMB1. To stop auditing SMB1 access, use the Windows PowerShell cmdlet Set-SmbServerConfiguration.
0xb0010bbb1011SMB1 server service has been automatically uninstalled.n Guidance: This event indicates that after detecting no attempts to contact this computer via the SMB1 protocol for %1 online days, the SMB1 Server service was automatically uninstalled.
0xb0010bcd1011The SMB server observed that the client doesn't support signing. Client name: %2 User Name: %4 Server requires signing: %5
0xb00200011011SMB2 Request Negotiate
0xb00200021011SMB2 Request Session Setup
0xb00200031011SMB2 Request Logoff
0xb00200041011SMB2 Request Tree Connect
0xb00200051011SMB2 Request Tree Disconnect
0xb00200061011SMB2 Request Echo
0xb00200071011SMB2 Request Cancel
0xb00200081011SMB2 Request Create
0xb00200091011SMB2 Request Close
0xb002000a1011SMB2 Request Flush
0xb002000b1011SMB2 Request Read
0xb002000c1011SMB2 Request Write
0xb002000d1011SMB2 Request Break Oplock
0xb002000e1011SMB2 Request Notify Break Lease
0xb002000f1011SMB2 Request Acknowledge Break Lease
0xb00200101011SMB2 Request Lock
0xb00200111011SMB2 Request Ioctl
0xb00200121011SMB2 Request Query Directory
0xb00200131011SMB2 Request Change Notify
0xb00200141011SMB2 Request Query Info
0xb00200151011SMB2 Request Set Info
0xb00200651011SMB2 Response Negotiate
0xb00200661011SMB2 Response Session Setup
0xb00200671011SMB2 Response Logoff
0xb00200681011SMB2 Response Tree Connect
0xb00200691011SMB2 Response Tree Disconnect
0xb002006a1011SMB2 Response Echo
0xb002006c1011SMB2 Response Create
0xb002006d1011SMB2 Response Close
0xb002006e1011SMB2 Response Flush
0xb002006f1011SMB2 Response Read
0xb00200701011SMB2 Response Write
0xb00200711011SMB2 Response Break Oplock
0xb00200731011SMB2 Response Acknowledge Break Lease
0xb00200741011SMB2 Response Lock
0xb00200751011SMB2 Response Ioctl
0xb00200761011SMB2 Response Query Directory
0xb00200771011SMB2 Response Change Notify
0xb00200781011SMB2 Response Query Info
0xb00200791011SMB2 Response Set Info
0xb002007a1011SMB2 Response Error
0xb00202271011SMB Session Authentication Failure Client Name: %11 Client Address: %6 User Name: %9 Session ID: %7 Status: %4 (%3) SPN: %12 SPN Validation Policy: %13 Guidance: You should expect this error when attempting to connect to shares using incorrect credentials. This error does not always indicate a problem with authorization, but mainly authentication. It is more common with non-Windows clients. This error can occur when using incorrect usernames and passwords with NTLM, mismatched LmCompatibility settings between client and server, an incorrect service principal name, duplicate Kerberos service principal names, incorrect Kerberos ticket-granting service tickets, or Guest accounts without Guest access enabled
0xb00203ed1011Negotiate integrity check failed. Status: %2 Client Name: %4 Client Address: %8 User Name: %6 Session ID: %9 Guidance: This event indicates that the client's negotiate request was altered on the network between the client and server due to errors or a "man-in-the-middle" attack. The client has been disconnected to prevent a security downgrade.
0xd00000011011SPN optional / no validation
0xd00000021011SPN optional / validate service name
0xd00000031011SPN optional / validate full
0xd00000041011SPN required / validate service name
0xd00000051011SPN required / validate full
0xd00000061011Stalled I/O
0xd00000071011Reopen durable handle failed
0xd00000081011Tdi
0xd00000091011Wsk
0xd000000a1011Rdma
0xd000000b1011Vmbus
0xd000000c1011Quic
0xd000000d1011Add
0xd000000e1011Update
0xd000000f1011Remove
0xd00000101011None
0xd00000111011Reconnect durable file
0xd00000121011RKF resume create
0xd00000131011Build create response
0xd00000141011N/A
0xd000001510112.0.2
0xd000001610112.1
0xd000001710113.0
0xd000001810113.0.2
0xd000001910113.1.1
0xd000001a1011closed
0xd000001b1011created
0xd000001c1011disabled
0xd000001d1011enabled
0xd000001e1011Error getting unicast ip address table for interface %2. %3
0xd000001f1011Error getting unicast ip address entry for interface %2. %3
0xd00000201011Error finding or adding the interface %2.
0xd00000211011DadState is different from IpDadStatePreferred for interface %2. Current DadState: %6.
0xd00000221011Error getting Nsi parameters for interface %2. %3
0xd00000231011Error allocating pool memory
0xd00000241011Error updating transport list for device %5. %3.
0xd00000251011Error allocating and getting table. %3.
0xd00000261011Notification type %6 is not supported. Nothing was done.
0xd00000271011Error getting Address from TransportName for interface %2. %3
0xd00000281011Error finding the address of the interface %2. %3
0xd00000291011Error because SMB Direct is not supported in interface %2. %3
0xd000002a1011Error initializing SMB in interface %2. %3
0xd000002b10Error initilizing the async handle. %4
0xd000002c10XsActSrv is not active.
0xd000002d10Pnp exception. %4
0xd000002e10Timeout on comleting pnp operation. %4
0xd000002f10Pnp operation took too long and it was never completed so it must be cancelled. %4
0xd000003010Error cancelling Pnp opearion. %4
0xd000003110NsiParameterNotification
0xd000003210NsiAddInstance
0xd000003310NsiDeleteInstance
0xd000003410NsiInitialNotification
0xd000003510MibParameterNotification
0xd000003610MibAddInstance
0xd000003710MibDeleteInstance
0xd000003810MibInitialNotification
0xd000003910Registry value defines properties for an FSCTL that has already been defined in another registry value.
0xd000003a10Registry value specifying FSCTL properties must also specify a non-zero FSCTL code.
0xd000003b10Registry value specifying FSCTL properties have the wrong format.
0xd000003c10Connection state has not changed.
0xd000003d10Connection timed out.
0xd000003e10The connection was idle and timed out.
0xd000003f10The server is stopping.
0xd000004010The endpoint is closing.
0xd000004110The connection is disconnected.
0xd000004210The idle connection is time out.
0xd000004310All channels are closed.
0xd000004410Decrypt message error.
0xd000004510Irrecoverable error.
0xd000004610Unauthenticated connection is closed.
0xd000004710Failed to send an interim async response.
0xd000004810Insufficient resources.
0xd000004910Connection/Stream shutdown without error.
0xd000004a10Connection/Stream shutdown unknown error.
0xd000004b10The event received is not supported.
0xd000004c10Invalid Parameter.
0xd000004d10The object is not found.
0xd000004e10Insufficient resources.
0xd000004f10Server can't create a new connection.
0xd000005010Server can't set bidi stream count for the connection.
0xd000005110Server can't get the local address.
0xd000005210Server close the connection.
0x1000000111Request
0x1000000211Response
0x1000000311Transition
0x1000000411Operational
0x1000000511Connection
0x1000000611Session
0x1000000711TreeConnect
0x1000000811File
0x1000000911Share
0x1000000a11Nsi
0x1000000b11Cert
0x1000000c11Quic
0x1000000d11Correlation
0x1000001111Rundown
0x1000001211ListenerRule
0x1000001311Interface
0x1000001411PerfOptional
0x1000001f11PacketStart
0x1000002011PacketEnd
0x1000002111SendPath
0x1000002211ReceivePath
0x1000002b11Packet
0x1000003011PduFull
0x7000000111Smb2RequestNegotiate
0x7000000211Smb2RequestSessionSetup
0x7000000311Smb2RequestLogoff
0x7000000411Smb2RequestTreeConnect
0x7000000511Smb2RequestTreeDisconnect
0x7000000611Smb2RequestEcho
0x7000000711Smb2RequestCancel
0x7000000811Smb2RequestCreate
0x7000000911Smb2RequestClose
0x7000000a11Smb2RequestFlush
0x7000000b11Smb2RequestRead
0x7000000c11Smb2RequestWrite
0x7000000d11Smb2RequestBreakOplock
0x7000000e11Smb2RequestNotifyBreakLease
0x7000000f11Smb2RequestAcknowledgeBreakLease
0x7000001011Smb2RequestLock
0x7000001111Smb2RequestIoctl
0x7000001211Smb2RequestQueryDirectory
0x7000001311Smb2RequestChangeNotify
0x7000001411Smb2RequestQueryInfo
0x7000001511Smb2RequestSetInfo
0x7000006511Smb2ResponseNegotiate
0x7000006611Smb2ResponseSessionSetup
0x7000006711Smb2ResponseLogoff
0x7000006811Smb2ResponseTreeConnect
0x7000006911Smb2ResponseTreeDisconnect
0x7000006a11Smb2ResponseEcho
0x7000006c11Smb2ResponseCreate
0x7000006d11Smb2ResponseClose
0x7000006e11Smb2ResponseFlush
0x7000006f11Smb2ResponseRead
0x7000007011Smb2ResponseWrite
0x7000007111Smb2ResponseBreakOplock
0x7000007311Smb2ResponseAcknowledgeBreakLease
0x7000007411Smb2ResponseLock
0x7000007511Smb2ResponseIoctl
0x7000007611Smb2ResponseQueryDirectory
0x7000007711Smb2ResponseChangeNotify
0x7000007811Smb2ResponseQueryInfo
0x7000007911Smb2ResponseSetInfo
0x7000007a11Smb2ResponseError
0x700000c811Smb2WorkItemTransition
0x700000c911Smb2WorkItemStart
0x700000ca11Smb2WorkItemStop
0x700000cb11Smb2WorkItemActivityTransfer
0x700000cc11Smb2WorkItemActivityStop
0x700001f411Smb2ConnectionAccept
0x700001f511Smb2ConnectionDisconnectEvent
0x700001f611Smb2ConnectionTerminate
0x7000022611Smb2SessionAllocate
0x7000022711Smb2SessionAuthFailure
0x7000022811Smb2SessionAuthenticated
0x7000022911Smb2SessionBind
0x7000022a11Smb2SessionTerminate
0x7000022b11Smb2SessionClose
0x7000025811Smb2TreeConnectAllocate
0x7000025911Smb2TreeConnectDisconnect
0x7000025a11Smb2TreeConnectTerminate
0x7000025b11Smb2TreeConnectFailedDueToPending
0x7000025c11Smb2TreeConnectForceClientReconnect
0x7000028a11Smb2FileOpen
0x7000028b11Smb2FileDisconnect
0x7000028c11Smb2FileReconnect
0x7000028d11Smb2FileSuspend
0x7000028e11Smb2FileClose
0x7000028f11Smb2FileTimeout
0x7000029011Smb2FileTerminate
0x7000029111Smb2FileCCFClose
0x7000029211Smb2FileCCFCloseAudit
0x700002bc11Smb2ShareAdd
0x700002bd11Smb2ShareModify
0x700002be11Smb2ShareDelete
0x7000038411SrvEmptyParameterTemplate
0x700003e811SrvS4U2SelfFailure
0x700003e911SrvDisabled
0x700003ea11Smb2RkfFailure
0x700003eb11SrvUnencryptedAcccessFailure
0x700003ec11SrvSignatureValidationFailure
0x700003ed11SrvNegotiateValidationFailure
0x700003ee11SrvShareAccessCheckFailure
0x700003ef11SrvShareAnonymousAccessDeniedFailure
0x700003f111SrvSessionAnonymousAccessDenied
0x700003f211SrvEndpointAdded
0x700003f311SrvEndpointRemoved
0x700003f411SrvNetNameInfoChange
0x700003f511SrvEndpointOnline
0x700003f611SrvEndpointOffline
0x700003f711SrvDecryptionFailure
0x700003f811SrvReopenFailure
0x700003f911SrvHandleScavenge
0x700003fa11SrvSessionInvalidate
0x700003fb11SrvFileInvalidate
0x700003fc11SrvSlowFsOperation
0x700003fd11SrvLmCompatibilityLevelNonDefault
0x700003fe11SrvFileSharingFirewallRuleEnabled
0x700003ff11SrvABESharesPresent
0x7000040011SrvSmb2Disabled
0x7000040111SrvNullSessionsAllowed
0x7000040211SrvLeasingDisabled
0x7000040311SrvFirewallPortsClosed
0x7000041e11SrvSlowNetworkOperation
0x7000070811SSClusterCaFailure
0x7000070911SSRkfCaFailure
0x700007d011SrvNetGetNextIdFailure
0x700007d111SrvNetConnectionEstablished
0x700007d211SrvNetClientCertificateChainRevocationChecksFailed
0x70000bbc11SrvAdminFileRundown
0x70000bbd11SrvAdminSessionRundown
0x70000bbe11SrvAdminShareRundown
0x70000bbf11Smb2MaxClusterDialectUpdated
0x70000bc011Smb2CipherSuiteOrder
0x70000bc111Smb2MdlIoCompletionFailure
0x70000bc211Srv2LiveDumpSucceeded
0x70000bc311Srv2LiveDumpThrotteled
0x70000bc411Srv2RDMASendEndpointNotification
0x70000bc511Srv2RDMASendEndpointNotificationFailure
0x70000bc611Srv2RDMAEndpointChange
0x70000bc711Srv2RDMAEndpointAllocationFailure
0x70000bc811Srv2RDMACreateListenerFailure
0x70000bc911Srv2RDMASendEndpointNotificationRPCFailure
0x70000bca11Srv2RDMANsiNotificationReceived
0x70000bcb11Srv2RDMAMibNotificationReceived
0x70000bcc11SrvAdminFsctlPropertiesListReadingFailure
0x70000bcd11SrvNetRdmaConnectionClosed
0x70000bce11ServerCertMappingExpiring
0x70000bcf11SrvNetQuicShutdownFailure
0x70000bd011ServerCertMappingUpdateFailure
0x70000bd111SrvNoNegotiatedCipher
0x70000bd211Smb2SlowCommand
0x70000bd311Smb2CommandTimeDistribution
0x70000bd411ServerCertMappingExpired
0x70000bd511Smb2ClosedEndpointsOutsideUnicastIPTable
0x70000bd611SrvNegotiateCipherFailure
0x70000bd711ServerCertMappingRestoreFailure
0x70000bd811ServerCertMappingRestoreSummary
0x70000bd911SrvNetRdmaRundownActive
0x70000bda11SrvNetRdmaRundownComplete
0x70000bdb11SrvNetRdmaReactivation
0x70000bdc11SrvNetRdmaReactivationComplete
0x70000bdd11SrvNetSmbDirectLoad
0x70000bde11Smb2DirectDataPlacementSecurityChanged
0x70000bdf11Smb2DialectChange
0x70000be011SecurityCertificateChanged
0x70000be111NoSmb1ObservedInLastPeriod
0x70000be211TdiModeEnabled
0x70000be311NsiTableAllocationFailed
0x70000be411NsiInterfaceAdded
0x70000be511NsiInterfaceRemoved
0x70000be611IPInterfaceNotFound
0x70000be711Srv2SessionKeyTooShort
0x70000be811ReceivedNullReparseBuffer
0x70000be911AllowListLoadFailed
0x70000bea11SrvNetQuicSendEndpointNotificationFailure
0x70000beb11SrvNetEventDisableRdmaListenSocketsState
0x70000bec11ServerCertificateFailure
0x70000bed11ShareQosPolicySettingFailure
0x70000bee11PacketFragment
0x70000bef11Packet
0x70000bf011AuditSmb1Access
0x70000bf111UninstallSmb1Server
0x70000bf211MutualAuthClientAccessDenied
0x70000bf311MutualAuthClientAccessAllowed
0x70000bf411SrvAdminMutualAuthClientAccessErrorShareRundown
0x70000bf511SrvNetAddEndpointListenerRulePortNotSupported
0x70000bf611SrvNetAddEndpointListenerRuleSuccess
0x70000bf711SrvNetAddEndpointListenerRuleFailure
0x70000bf811SrvNetAddListenerRuleNew
0x70000bf911SrvNetAddListenerRuleUpdate
0x70000bfa11SrvNetAddListenerRuleRemove
0x70000bfb11SrvNetEnableImplicitLoopbackInterfaceError
0x70000bfc11SrvNetDisableImplicitLoopbackInterfaceError
0x70000bfd11SrvNetComponentCapabilities
0x70000bfe11AlternativePortFirewallRuleAlreadyAdded
0x70000bff11AlternativePortFirewallRuleAddFailure
0x70000c0011AlternativePortFirewallRuleAddSuccess
0x70000c0111Smb2ClientDoesNotSupportSigning
0x70000c0211Smb2ClientDoesNotSupportEncryption
0x70000c0311InsecureGuestLogon
0x70000c0411Smb2ShareConnectionEstablished
0x70000c0511SrvNetClientDoesNotSupportSpn
0x70000c0611SrvNetClientSentUnrecognizedSpn
0x70000c0711SrvNetClientSentEmptySpn
0x70000c0811Smb1ClientDoesNotSupportSigning
0xb000025c11A client connection to a continuously available share has been marked so that the client will be forced to reconnect to the server node with best possible storage connectivity. Session ID: %1 TreeConnect ID: %2 Share: %4
0xb000025d11A client request on a continuously available share has been failed so that the client will be forced to reconnect to the server node with best possible storage connectivity. Session ID: %1 TreeConnect ID: %2 Share: %4
0xb00003eb11The server received an unencrypted message. Message was rejected. Client Name: %4 Guidance: This event indicates that a client is sending unencrypted data even though the SMB share requires encryption.
0xb00003ec11The server received an incorrectly signed message. Message was rejected. Client Name: %2 Guidance: This event indicates that a client is sending an incorrectly signed request.
0xb000041411Quic connection shutdown. Error: %1 Reason: %2 Endpoint Name: %4 Transport Name: %6 Guidance: This event indicates that the winquic connection is shutting down by the server. This event commonly occurs because the server certificate mapping is not created. It may also be caused by the server failed to configure the winquic connections.
0xb000041611The server received a request and the server requires encryption, but the server and client did not negotiate an encryption cipher, nor does server allow unencrypted access. Request: %10 Client Name: %4 Client Address: %8 User Name: %6 Session ID: %9 Share Name: %2 Guidance: This event indicates that client is trying to access a server that requires encryption, but no cipher was negotiated, and server does not allow unencrypted access. Check HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\RejectUnencryptedAccess to see if the value has been changed.
0xb000041711The server received a %2 request but is taking an abnormal amount of time to process it. Instance Id: %1 Command: %2 PerfBlock: %3 Duration(s): %4 Threshold(s): %5
0xb000041811The server processed a %1 request. Times taken to complete each stage below. Command: %1 AcquireLockTime(s): %2 IoTime(s): %3 TotalTime(s): %4 Threshold(s): %5
0xb000041911The certificate for the server has expired. Subject: %2 Thumbprint: %4 Expires on %5. Guidance: This event indicates the certificate has expired. Renew or issue new certificates to avoid service interruption.
0xb000041a11Found %1 endpoint(s) related to interface ID %2, closed %3 of which.
0xb000041b11The SMB negotiate request processing failed on the server to select the encryption cipher for the client and server. Please ensure there is a common cipher between the client and server. Client encryption cipher suite order (most to least preferred): %2 Server encryption cipher suite order (most to least preferred): %4
0xb000041c11Failed to restore a server certificate mapping from persistent storage. Subject: %2 Thumbprint: %4 Error code: %5.
0xb000041d11Restored %2 of %1 server certificate mappings from persistent storage. Last error code: %3.
0xb000041e11Network operation has taken longer than expected. Client Name: %8 Client Address: %10 User Name: %6 Session ID: %3 Share Name: %12 File Name: %14 Command: %1 Duration (in milliseconds): %15 Warning Threshold (in milliseconds): %16 Guidance: The underlying file system has taken too long to respond to an operation. This typically indicates a problem with the storage and not SMB.
0xb000041f11RDMA rundown is active. Active RDMA-based operations will be wound down. There are currently %1 active RDMA resources.
0xb000042011RDMA rundown is complete. No further RDMA-based operations are allowed. Rundown no-op: %1.
0xb000042111Reactivation of RDMA support has commenced.
0xb000042211RDMA is no longer disabled. RDMA-based operations can proceed, given hardware capabilities and OS policy. No-op: %1.
0xb000042311SMBDirect load attempt complete. Success: %1 Status code: %2 Service path: %4
0xb000042411SMB DDP security changed from %1 to %2.
0xb000042511SMB2 Request Negotiate Dialect Failure Session ID: %1 Client Address: %18 Client Name:%20 Client Dialects: %12 Minimum dialect required by server: %15 Maximum dialect required by server: %16 Guidance: You should expect this error when servers don't meet the dialects requested by client. Please check the minimum and maximum dialects set by the client and ensure the server supports the dialects.
0xb000042611SMB Dialect Change %1 was changed from %2 to %3.
0xb000043811Component capabilities: %1 Internal patch number: %2
0xb000077211Session key for connection is weaker than required. Connection will be closed as a result. Client: %2 User: %6 Session key length: %3 Required Session key length: %4 Guidance: To establish a connection with a shorter session key, set the following registry DWORD value name with the value as decimal bits: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters] "MinimumSessionKeyLength" Important: If you have configured the 'Network security: Configure encryption types allowed for Kerberos' security policy to prevent use of 256-bit keys but also set the MinimumSessionKeyLength greater than 128 bits, the computer will not be able to make SMB connections. Setting MinimumSessionKeyLength higher than 128 bits will also prevent SMB connections using NTLM.
0xb000077311Server received STATUS_STOPPED_ON_SYMLINK but the reparse buffer is NULL.
0xb000077411Custom FSCTL allow list was not successfully loaded after several retries.
0xb000077511Send QUIC Endpoint notification failure - %1
0xb000077611RDMA listen socket disable override is %1. New value is %2. SrvNetIsRDMASupportEnabled is %3. Action taken %4.
0xb000077711Server Certificate failure - %1
0xb000077811Warning to set the QoS policy on file %6. Status=%1
0xb000077911The SMB connection was successfully established. Endpoint Name: %2 Transport: %3 Server socket address: %5 Client socket address: %7 Connection ID: %9 Mutual authentication: %10 Access control: %11
0xb000077a11The server was unable to perform revocation checks on the client certificate chain. The connection will proceed. Verification Status: %1 Endpoint Name: %3 Transport: %4 Server socket address: %6 Client socket address: %8 Connection ID: %10
0xb0000bbc11SMB server admin file rundown
0xb0000bbd11SMB server admin session rundown
0xb0000bbe11SMB server admin share rundown
0xb0000bbf11Access Denied Server certificate mapping name: %2 Client socket address: %4 Client certificate chain: Subject, Issuer, Serial Number, %6 %8 Deny entries: %10 Allow Entries: %12 Guidance: The server denied access to the client during mutual authentication. If you did not expect this result, examine the deny and allow entries above. For more information on troubleshooting this behavior, review https://go.microsoft.com/fwlink/?linkid=2243808
0xb0000bc011Access Allowed Server certificate mapping name: %2 Client socket address: %4 Client certificate chain: Subject, Issuer, Serial Number, %6 %8 Deny entries: %10 Allow Entries: %12 Guidance: The server allowed access to the client during mutual authentication. If you did not expect this result, examine the deny and allow entries above. For more information on troubleshooting this behavior, review https://go.microsoft.com/fwlink/?linkid=2243809
0xb0000bc111An error occurred while checking client certificate chain access during mutual authentication. Win32 error code: %1 Server certificate mapping name: %3 Client socket address: %5 Guidance: For more information on troubleshooting this behavior, review https://go.microsoft.com/fwlink/?linkid=2243709
0xb0000bc211An administrator attempted to assign an alternative SMB server listener port %1, but it is either in the 0―1024 reserved range or it is already assigned to another process. Use NETSTAT -abno to list all listening ports and their processes in use on this computer.
0xb0000bc311The SMB server service created an endpoint with the following listener rule entry settings: Transport: %2 Port: %3 TransportType: %4 SrvInstances: %5 Guidance: You should expect this event when assigning alternative SMB server listener ports and on any subsequent restarts of the SMB server service.
0xb0000bc411The SMB server service failed to create an endpoint with the following listener rule entry settings: Transport: %2 Port: %3 TransportType: %4 SrvInstances: %5 Error: %6 Guidance: This error is usually caused by another process already listening on the same IP address and port. Use NETSTAT -abno to list all listening ports and their processes in use on this computer.
0xb0000bc511An administrator created an alternative SMB server listener port rule entry: Port: %1 TransportType: %2 SrvInstances: %3 Guidance: SMB clients can now connect to this alternative SMB server listener port.
0xb0000bc611An administrator updated an existing alterative SMB server listener port rule entry: Port: %1 TransportType: %2 SrvInstances: %3 Guidance: SMB clients can now connect to this updated alternative SMB server listener port.
0xb0000bc711An administrator removed an existing alternative SMB server listener port rule entry: Port: %1 TransportType: %2 SrvInstances: %3 Guidance: This will close the specified listening sockets for the transport type on the specified port number. SMB clients cannot connect to this SMB server on that alternative port anymore.
0xb0000bc811The SMB server service failed to enable an implicit loopback interface for interface %1 with NTSTATUS %2.
0xb0000bc911The SMB server service failed to disable an implicit loopback interface for interface %1 with NTSTATUS %2.
0xb0000bca11The inbound %2 firewall rule already exists for port %1.
0xb0000bcb11The inbound %2 firewall rule failed to be created for port %1.
0xb0000bcc11The inbound %2 firewall rule was successfully created for port %1.
0xb0000bce11The SMB server observed that the client doesn't support encryption. Client name: %2 Server requires encryption: %3
0xb0000bcf11The SMB client was logged on as Guest account. Client name: %2
0xb0000fa011The SMB client connection to the share was established. Share name: %2 Client name: %6 Client address: %4 Session ID: %7 Tree ID: %8 Transport type: %9 Signing used: %10 Encryption used: %11 Compression activated: %12
0xb001042311SMBDirect load attempt complete. Success: %1 Status code: %2 Service path: %4 Device name: %6
0xb001077611RDMA listen socket disable override is %1. New value is %2. SrvNetEnableRdmaSupport is %3. Aggregate RDMA enable/policy evaluation is %4. SKU support %5. Action taken %6.
0xb001077a11The server was unable to perform revocation checks on the client certificate chain. The connection will proceed. Verification Status: %1 Endpoint Name: %3 Transport: %4 Transport Name: %6 Client socket address: %8
0xb0010bbf11Access Denied Server certificate mapping name: %2 Client socket address: %4 Connection ID: %14 Client certificate chain: Subject, Issuer, Serial Number, %6 %8 Deny entries: %10 Allow Entries: %12 Guidance: The server denied access to the client during mutual authentication. If you did not expect this result, examine the deny and allow entries above. For more information on troubleshooting this behavior, review https://go.microsoft.com/fwlink/?linkid=2243808
0xb0010bc011Access Allowed Server certificate mapping name: %2 Client socket address: %4 Connection ID: %14 Client certificate chain: Subject, Issuer, Serial Number, %6 %8 Deny entries: %10 Allow Entries: %12 Guidance: The server allowed access to the client during mutual authentication. If you did not expect this result, examine the deny and allow entries above. For more information on troubleshooting this behavior, review https://go.microsoft.com/fwlink/?linkid=2243809
0xb0010bc111An error occurred while checking client certificate chain access during mutual authentication. Win32 error code: %1 Server certificate mapping name: %3 Client socket address: %5 Connection ID: %7 Guidance: For more information on troubleshooting this behavior, review https://go.microsoft.com/fwlink/?linkid=2243709
0xd000002b11Error due to active rundown of RDMA for interface %2. %3
0xd000002c11Error initilizing the async handle. %4
0xd000002d11XsActSrv is not active.
0xd000002e11Pnp exception. %4
0xd000002f11Timeout on comleting pnp operation. %4
0xd000003011Pnp operation took too long and it was never completed so it must be cancelled. %4
0xd000003111Error cancelling Pnp opearion. %4
0xd000003211NsiParameterNotification
0xd000003311NsiAddInstance
0xd000003411NsiDeleteInstance
0xd000003511NsiInitialNotification
0xd000003611MibParameterNotification
0xd000003711MibAddInstance
0xd000003811MibDeleteInstance
0xd000003911MibInitialNotification
0xd000003a11Registry value defines properties for an FSCTL that has already been defined in another registry value.
0xd000003b11Registry value specifying FSCTL properties must also specify a non-zero FSCTL code.
0xd000003c11Registry value specifying FSCTL properties have the wrong format.
0xd000003d11Error getting unicast ip address table for interface %2. %3
0xd000003e11Error finding or adding the interface %2.
0xd000003f11Error getting Nsi parameters for interface %2. %3
0xd000004011Error certificate for mapping not found in store. Name: %4 Thumbprint: %6
0xd000004111Error not enough memory to complete certificate routine Name: %4 Thumbprint: %6
0xd000004211Error certificate is already registered Name: %4 Thumbprint: %6
0xd000004311Connection state has not changed.
0xd000004411Connection timed out.
0xd000004511The connection was idle and timed out.
0xd000004611The server is stopping.
0xd000004711The endpoint is closing.
0xd000004811The connection is disconnected.
0xd000004911The idle connection is time out.
0xd000004a11All channels are closed.
0xd000004b11Decrypt message error.
0xd000004c11Irrecoverable error.
0xd000004d11Unauthenticated connection is closed.
0xd000004e11Failed to send an interim async response.
0xd000004f11Insufficient resources.
0xd000005011Decompression error.
0xd000005111SMB transform header are malformed.
0xd000005211Connection/Stream shutdown without error.
0xd000005311Connection/Stream shutdown unknown error.
0xd000005411The event received is not supported.
0xd000005511Invalid Parameter.
0xd000005611The object is not found.
0xd000005711Insufficient resources.
0xd000005811The certificate is not trusted.
0xd000005911The certificate is expired.
0xd000005a11The certificate is revoked.
0xd000005b11Mutual authentication failed.
0xd000005c11The SMB client was denied access to the SMB server during mutual authentication.
0xd000005d11Server can't create a new connection.
0xd000005e11Server can't set bidi stream count for the connection.
0xd000005f11Server can't get the local address.
0xd000006011Server close the connection.
0xd000006111The client certificate validation by Schannel failed.
0xd000006211The client certificate access check failed.
0xd000006311The client certificate access check RPC failed.
0xd000006411QUIC returned an error during the asynchronous client certificate validation.
0xd000006511None
0xd000006611NTLM
0xd000006711Kerberos
0xd000006811PKU2U
0xd000006911Negotiate
0xd000006a11Session setup
0xd000006b11Logoff
0xd000006c11Tree connect
0xd000006d11Tree disconnect
0xd000006e11Create
0xd000006f11Close
0xd000007011Flush
0xd000007111Read
0xd000007211Write
0xd000007311Lock
0xd000007411Ioctl
0xd000007511Cancel
0xd000007611Echo
0xd000007711Query directory
0xd000007811Change notify
0xd000007911Query info
0xd000007a11Set info
0xd000007b11Oplock break
0xd000007c11The server closed the session.
0xd000007d11The server closed the session due to it idling past the AutoDisconnectTimeout time.
0xd000007e11The server closed the session due to it being forcibly closed.
0xd000007f11SRV_PRIMARY_INSTANCE
0xd000008011SRV_CSV_INSTANCE
0xd000008111SRV_SBL_INSTANCE
0xd000008211SRV_SR_INSTANCE
0xd000008311Security Transforms Disabled
0xd000008411Security Transforms Enabled
0xd000008511Security Transforms Enabled (Except For Shares Enabled With Isolated Transport)
0xd000008611SrvNetTransportTypeTdi
0xd000008711SrvNetTransportTypeTcpip
0xd000008811SrvNetTransportTypeRdma
0xd000008911SrvNetTransportTypeVmBus
0xd000008a11SrvNetTransportTypeQuic
0xd000008b11N/A
0xd000008c11Default
0xd000008d11CSV
0xd000008e11Default, CSV
0xd000008f11SBL
0xd000009011Default, SBL
0xd000009111CSV, SBL
0xd000009211Default, CSV, SBL
0xd000009311SR
0xd000009411Default, SR
0xd000009511CSV, SR
0xd000009611Default, CSV, SR
0xd000009711SBL, SR
0xd000009811Default, SBL, SR
0xd000009911CSV, SBL, SR
0xd000009a11Default, CSV, SBL, SR
0xd000009b11No
0xd000009c11Yes
0xd000009d11TCP
0xd000009e11UDP
0xd000009f11The SMB2_GLOBAL_CAP_ENCRYPTION flag is not set in the Capabilities field of the SMB2 NEGOTIATE request.
0xd00000a011The CipherCount field of the SMB2 NEGOTIATE request is 0.
0xf000000111Supports RDMA via SMBDirect
0xf000000211Supports runtime unlinking from SMBDirect
626 entries