Windows 10: Event 5061 - Cryptographic Operation. Windows 11 Pro 22H2 22621.2134 WFEP 1000.22659.100.0

Discus and support Event 5061 - Cryptographic Operation. Windows 11 Pro 22H2 22621.2134 WFEP 1000.22659.100.0 in Windows 10 Software and Apps to solve the problem; Above is a Screen Shot of the Event ID 5061 and my System Info. Occurs on every reboot. LSASS I'm aware there is another post about this, however, it... Discussion in 'Windows 10 Software and Apps' started by Roe Paul M, Aug 20, 2023.

  1. Event 5061 - Cryptographic Operation. Windows 11 Pro 22H2 22621.2134 WFEP 1000.22659.100.0


    Above is a Screen Shot of the Event ID 5061 and my System Info. Occurs on every reboot. LSASS I'm aware there is another post about this, however, it has been closed and there was never a real resolution from what I could see other than they were on build 1803 and went to 1903 to resolve it. I am not on those builds.

    :)
     
    Roe Paul M, Aug 20, 2023
    #1
  2. glnz Win User

    Audit failures every reboot - Event 5061 - Cryptographic operation.

    fdegrove - sorry, no luck. Disabled all three, rebooted and got again two Audit Failures.
    (By the way, my plain old Dell Optiplex PC never had a smart card reader as far as I know.)
    But that was a great idea.
    Did you see my third post in this thread, at Audit failures every reboot - Event 5061 - Cryptographic operation. ?

    EDIT - Am I missing a Certificate with the name "Microsoft Connected Devices Platform"? That's indicated as "Key name" in the eventvwr data.
     
  3. EdTittel Win User
    Audit failures every reboot - Event 5061 - Cryptographic operation.

    Just FYI, anything associated with the S-1-5-18 SID is associated with the "Local System" account. It represents working objects the the OS creates and uses as it engages in normal operations. Here's a snip from that ever-so-fascinating MS Support document Well-known security identifiers in Windows operating systems


    Event 5061 - Cryptographic Operation. Windows 11 Pro 22H2 22621.2134 WFEP 1000.22659.100.0 237741d1560952509t-audit-failures-every-reboot-event-5061-cryptographic-operation-image.png


    HTH,
    --Ed--
     
    EdTittel, Aug 20, 2023
    #3
  4. glnz Win User

    Event 5061 - Cryptographic Operation. Windows 11 Pro 22H2 22621.2134 WFEP 1000.22659.100.0

    Audit failures every reboot - Event 5061 - Cryptographic operation.

    Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit version 1803. ‎4/‎28/‎2019

    Immediately after every reboot of Win 10 Pro 64-bit version 1803, in Event Viewer, there are between two and four Audit Failures for something related to Cryptography. So my Win 10 machine is insecure? I have run sfc /scannow and Dism /Online /Cleanup-Image /RestoreHealth many times, with no luck. And I hardly even use my Win 10 machine - there are almost no apps on it yet. My actual Win 10 build is 17134.706

    Here are the latest five Cryptography-related Audit Failures, from two reboots:

    LATEST OF FIVE:Log Name: Security
    Source: Microsoft-Windows-Security-Auditing
    Date: 4/28/2019 12:27:52 PM
    Event ID: 5061
    Task Category: System Integrity
    Level: Information
    Keywords: Audit Failure
    User: N/A
    Computer: DESKTOP-3#####N
    Description:
    Cryptographic operation.

    Subject:
    Security ID: DESKTOP-3#####N\[My user name]
    Account Name: [My user name]
    Account Domain: DESKTOP-3#####N
    Logon ID: 0x3EC24

    Cryptographic Parameters:
    Provider Name: Microsoft Software Key Storage Provider
    Algorithm Name: UNKNOWN
    Key Name: Microsoft Connected Devices Platform device certificate
    Key Type: User key.

    Cryptographic Operation:
    Operation: Open Key.
    Return Code: 0x80090016
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>5061</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>12290</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2019-04-28T16:27:52.339705400Z" />
    <EventRecordID>19582</EventRecordID>
    <Correlation />
    <Execution ProcessID="880" ThreadID="948" />
    <Channel>Security</Channel>
    <Computer>DESKTOP-3#####N</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="SubjectUserSid">S-1-5-21-3591163430-416291016-3566129944-1001</Data>
    <Data Name="SubjectUserName">[My user name]</Data>
    <Data Name="SubjectDomainName">DESKTOP-3#####N</Data>
    <Data Name="SubjectLogonId">0x3ec24</Data>
    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
    <Data Name="AlgorithmName">UNKNOWN</Data>
    <Data Name="KeyName">Microsoft Connected Devices Platform device certificate</Data>
    <Data Name="KeyType">%%2500</Data>
    <Data Name="Operation">%%2480</Data>
    <Data Name="ReturnCode">0x80090016</Data>
    </EventData>
    </Event>

    FOURTH OF FIVE:Log Name: Security
    Source: Microsoft-Windows-Security-Auditing
    Date: 4/28/2019 12:26:51 PM
    Event ID: 5061
    Task Category: System Integrity
    Level: Information
    Keywords: Audit Failure
    User: N/A
    Computer: DESKTOP-3#####N
    Description:
    Cryptographic operation.

    Subject:
    Security ID: LOCAL SERVICE
    Account Name: LOCAL SERVICE
    Account Domain: NT AUTHORITY
    Logon ID: 0x3E5

    Cryptographic Parameters:
    Provider Name: Microsoft Software Key Storage Provider
    Algorithm Name: UNKNOWN
    Key Name: [Hex number]
    Key Type: User key.

    Cryptographic Operation:
    Operation: Open Key.
    Return Code: 0x80090016
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>5061</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>12290</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2019-04-28T16:26:51.704606400Z" />
    <EventRecordID>19552</EventRecordID>
    <Correlation />
    <Execution ProcessID="880" ThreadID="1004" />
    <Channel>Security</Channel>
    <Computer>DESKTOP-3#####N</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="SubjectUserSid">S-1-5-19</Data>
    <Data Name="SubjectUserName">LOCAL SERVICE</Data>
    <Data Name="SubjectDomainName">NT AUTHORITY</Data>
    <Data Name="SubjectLogonId">0x3e5</Data>
    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
    <Data Name="AlgorithmName">UNKNOWN</Data>
    <Data Name="KeyName">[Hex number]</Data>
    <Data Name="KeyType">%%2500</Data>
    <Data Name="Operation">%%2480</Data>
    <Data Name="ReturnCode">0x80090016</Data>
    </EventData>
    </Event>

    THIRD OF FIVE:Log Name: Security
    Source: Microsoft-Windows-Security-Auditing
    Date: 4/28/2019 11:29:28 AM
    Event ID: 5061
    Task Category: System Integrity
    Level: Information
    Keywords: Audit Failure
    User: N/A
    Computer: DESKTOP-3#####N
    Description:
    Cryptographic operation.

    Subject:
    Security ID: DESKTOP-3#####N\[My user name]
    Account Name: [My user name]
    Account Domain: DESKTOP-3#####N
    Logon ID: 0x3EF94

    Cryptographic Parameters:
    Provider Name: Microsoft Software Key Storage Provider
    Algorithm Name: UNKNOWN
    Key Name: Microsoft Connected Devices Platform device certificate
    Key Type: User key.

    Cryptographic Operation:
    Operation: Open Key.
    Return Code: 0x80090016
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>5061</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>12290</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2019-04-28T15:29:28.196237300Z" />
    <EventRecordID>19387</EventRecordID>
    <Correlation />
    <Execution ProcessID="884" ThreadID="928" />
    <Channel>Security</Channel>
    <Computer>DESKTOP-3#####N</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="SubjectUserSid">S-1-5-21-3591163430-416291016-3566129944-1001</Data>
    <Data Name="SubjectUserName">[My user name]</Data>
    <Data Name="SubjectDomainName">DESKTOP-3#####N</Data>
    <Data Name="SubjectLogonId">0x3ef94</Data>
    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
    <Data Name="AlgorithmName">UNKNOWN</Data>
    <Data Name="KeyName">Microsoft Connected Devices Platform device certificate</Data>
    <Data Name="KeyType">%%2500</Data>
    <Data Name="Operation">%%2480</Data>
    <Data Name="ReturnCode">0x80090016</Data>
    </EventData>
    </Event>

    SECOND OF FIVE:Log Name: Security
    Source: Microsoft-Windows-Security-Auditing
    Date: 4/28/2019 11:28:27 AM
    Event ID: 5061
    Task Category: System Integrity
    Level: Information
    Keywords: Audit Failure
    User: N/A
    Computer: DESKTOP-3#####N
    Description:
    Cryptographic operation.

    Subject:
    Security ID: LOCAL SERVICE
    Account Name: LOCAL SERVICE
    Account Domain: NT AUTHORITY
    Logon ID: 0x3E5

    Cryptographic Parameters:
    Provider Name: Microsoft Software Key Storage Provider
    Algorithm Name: UNKNOWN
    Key Name: [Hex number]
    Key Type: User key.

    Cryptographic Operation:
    Operation: Open Key.
    Return Code: 0x80090016
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>5061</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>12290</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2019-04-28T15:28:27.709849300Z" />
    <EventRecordID>19363</EventRecordID>
    <Correlation />
    <Execution ProcessID="884" ThreadID="992" />
    <Channel>Security</Channel>
    <Computer>DESKTOP-3#####N</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="SubjectUserSid">S-1-5-19</Data>
    <Data Name="SubjectUserName">LOCAL SERVICE</Data>
    <Data Name="SubjectDomainName">NT AUTHORITY</Data>
    <Data Name="SubjectLogonId">0x3e5</Data>
    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
    <Data Name="AlgorithmName">UNKNOWN</Data>
    <Data Name="KeyName">[Hex number]</Data>
    <Data Name="KeyType">%%2500</Data>
    <Data Name="Operation">%%2480</Data>
    <Data Name="ReturnCode">0x80090016</Data>
    </EventData>
    </Event>

    FIRST OF FIVE:Log Name: Security
    Source: Microsoft-Windows-Security-Auditing
    Date: 4/28/2019 11:28:27 AM
    Event ID: 5061
    Task Category: System Integrity
    Level: Information
    Keywords: Audit Failure
    User: N/A
    Computer: DESKTOP-3#####N
    Description:
    Cryptographic operation.

    Subject:
    Security ID: LOCAL SERVICE
    Account Name: LOCAL SERVICE
    Account Domain: NT AUTHORITY
    Logon ID: 0x3E5

    Cryptographic Parameters:
    Provider Name: Microsoft Software Key Storage Provider
    Algorithm Name: UNKNOWN
    Key Name: [Hex number]
    Key Type: User key.

    Cryptographic Operation:
    Operation: Open Key.
    Return Code: 0x80090016
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>5061</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>12290</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2019-04-28T15:28:27.709849300Z" />
    <EventRecordID>19363</EventRecordID>
    <Correlation />
    <Execution ProcessID="884" ThreadID="992" />
    <Channel>Security</Channel>
    <Computer>DESKTOP-3#####N</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="SubjectUserSid">S-1-5-19</Data>
    <Data Name="SubjectUserName">LOCAL SERVICE</Data>
    <Data Name="SubjectDomainName">NT AUTHORITY</Data>
    <Data Name="SubjectLogonId">0x3e5</Data>
    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
    <Data Name="AlgorithmName">UNKNOWN</Data>
    <Data Name="KeyName">[Hex number]</Data>
    <Data Name="KeyType">%%2500</Data>
    <Data Name="Operation">%%2480</Data>
    <Data Name="ReturnCode">0x80090016</Data>
    </EventData>
    </Event>
    So, what the *** are these, and how do we fix? No guesses - just the real fix.

    Thanks.
     
Thema:

Event 5061 - Cryptographic Operation. Windows 11 Pro 22H2 22621.2134 WFEP 1000.22659.100.0

Loading...
  1. Event 5061 - Cryptographic Operation. Windows 11 Pro 22H2 22621.2134 WFEP 1000.22659.100.0 - Similar Threads - Event 5061 Cryptographic

  2. Related to Operation Code in Event ID 5061 - Crptopgrahic operation

    in Windows 10 Gaming
    Related to Operation Code in Event ID 5061 - Crptopgrahic operation: Log Name: SecuritySource: Microsoft-Windows-Security-AuditingDate: 2023-11-18 12:45:30Event ID: 5061Task Category: System IntegrityLevel: InformationKeywords: Audit SuccessUser: N/AComputer: SERVER01.domain.localEvent DescriptionA cryptographic operation was...
  3. Related to Operation Code in Event ID 5061 - Crptopgrahic operation

    in Windows 10 Software and Apps
    Related to Operation Code in Event ID 5061 - Crptopgrahic operation: Log Name: SecuritySource: Microsoft-Windows-Security-AuditingDate: 2023-11-18 12:45:30Event ID: 5061Task Category: System IntegrityLevel: InformationKeywords: Audit SuccessUser: N/AComputer: SERVER01.domain.localEvent DescriptionA cryptographic operation was...
  4. Event 5061 - Cryptographic Operation. Windows 11 Pro 22H2 22621.2134 WFEP 1000.22659.100.0

    in Windows 10 Gaming
    Event 5061 - Cryptographic Operation. Windows 11 Pro 22H2 22621.2134 WFEP 1000.22659.100.0: Above is a Screen Shot of the Event ID 5061 and my System Info. Occurs on every reboot. LSASS I'm aware there is another post about this, however, it has been closed and there was never a real resolution from what I could see other than they were on build 1803 and went to...
  5. Windows 11 - 1400 Events with this error Cryptographic Operation failed. Microsoft...

    in Windows 10 Gaming
    Windows 11 - 1400 Events with this error Cryptographic Operation failed. Microsoft...: Hello,I have a new notebook Lenovo updated to Windows 11 and my PC reboots without visible reasons. There are thousands of errors in events viewer:The most frequent is this oneCryptographic Operation failed. Cryptographic Parameters: OperationType: 16 Provider Name:...
  6. Windows 11 - 1400 Events with this error Cryptographic Operation failed. Microsoft...

    in Windows 10 Software and Apps
    Windows 11 - 1400 Events with this error Cryptographic Operation failed. Microsoft...: Hello,I have a new notebook Lenovo updated to Windows 11 and my PC reboots without visible reasons. There are thousands of errors in events viewer:The most frequent is this oneCryptographic Operation failed. Cryptographic Parameters: OperationType: 16 Provider Name:...
  7. Windows 11 - 1400 Events with this error Cryptographic Operation failed. Microsoft...

    in Windows 10 BSOD Crashes and Debugging
    Windows 11 - 1400 Events with this error Cryptographic Operation failed. Microsoft...: Hello,I have a new notebook Lenovo updated to Windows 11 and my PC reboots without visible reasons. There are thousands of errors in events viewer:The most frequent is this oneCryptographic Operation failed. Cryptographic Parameters: OperationType: 16 Provider Name:...
  8. Audit failures every reboot - Event 5061 - Cryptographic operation.

    in Windows 10 Support
    Audit failures every reboot - Event 5061 - Cryptographic operation.: Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit version 1803. ‎4/‎28/‎2019 Immediately after every reboot of Win 10 Pro 64-bit version 1803, in Event Viewer, there are between two and four Audit Failures for something related to...
  9. Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit

    in Windows 10 BSOD Crashes and Debugging
    Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit: Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit version 1803. ‎4/‎28/‎2019 Immediately after every reboot of Win 10 Pro 64-bit version 1803, in Event Viewer, there are between two and four Audit Failures for something related to...
  10. Event ID 5061

    in Windows 10 Support
    Event ID 5061: Alright so both today and on June 23 I had gotten these audit failures that go like this. Cryptographic operation.Subject: Security ID: DESKTOP-7V82FOC\Owner Account Name: Owner Account Domain: DESKTOP-7V82FOC Logon ID: 0x3DB3FCryptographic Parameters: Provider Name:...