Windows 10: Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit

Discus and support Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit in Windows 10 BSOD Crashes and Debugging to solve the problem; Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit version 1803. ‎4/‎28/‎2019 Immediately after every reboot of... Discussion in 'Windows 10 BSOD Crashes and Debugging' started by glnzglnz, Apr 28, 2019.

  1. glnzglnz Win User

    Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit


    Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit version 1803. ‎4/‎28/‎2019


    Immediately after every reboot of Win 10 Pro 64-bit version 1803, in Event Viewer, there are between two and four Audit Failures for something related to Cryptography. So my Win 10 machine is insecure? I have run sfc /scannow and Dism /Online /Cleanup-Image /RestoreHealth many times, with no luck. And I hardly even use my Win 10 machine - there are almost no apps on it yet. My actual Win 10 build is 17134.706


    Here are the latest five Cryptography-related Audit Failures, from two reboots:


    LATEST OF FIVE:

    Log Name: Security
    Source: Microsoft-Windows-Security-Auditing
    Date: 4/28/2019 12:27:52 PM
    Event ID: 5061
    Task Category: System Integrity
    Level: Information
    Keywords: Audit Failure
    User: N/A
    Computer: DESKTOP-3#####N
    Description:
    Cryptographic operation.

    Subject:
    Security ID: DESKTOP-3#####N\[My user name]
    Account Name: [My user name]
    Account Domain: DESKTOP-3#####N
    Logon ID: 0x3EC24

    Cryptographic Parameters:
    Provider Name: Microsoft Software Key Storage Provider
    Algorithm Name: UNKNOWN
    Key Name: Microsoft Connected Devices Platform device certificate
    Key Type: User key.

    Cryptographic Operation:
    Operation: Open Key.
    Return Code: 0x80090016
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>5061</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>12290</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2019-04-28T16:27:52.339705400Z" />
    <EventRecordID>19582</EventRecordID>
    <Correlation />
    <Execution ProcessID="880" ThreadID="948" />
    <Channel>Security</Channel>
    <Computer>DESKTOP-3#####N</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="SubjectUserSid">S-1-5-21-3591163430-416291016-3566129944-1001</Data>
    <Data Name="SubjectUserName">[My user name]</Data>
    <Data Name="SubjectDomainName">DESKTOP-3#####N</Data>
    <Data Name="SubjectLogonId">0x3ec24</Data>
    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
    <Data Name="AlgorithmName">UNKNOWN</Data>
    <Data Name="KeyName">Microsoft Connected Devices Platform device certificate</Data>
    <Data Name="KeyType">%%2500</Data>
    <Data Name="Operation">%%2480</Data>
    <Data Name="ReturnCode">0x80090016</Data>
    </EventData>
    </Event>



    FOURTH OF FIVE:

    Log Name: Security
    Source: Microsoft-Windows-Security-Auditing
    Date: 4/28/2019 12:26:51 PM
    Event ID: 5061
    Task Category: System Integrity
    Level: Information
    Keywords: Audit Failure
    User: N/A
    Computer: DESKTOP-3#####N
    Description:
    Cryptographic operation.

    Subject:
    Security ID: LOCAL SERVICE
    Account Name: LOCAL SERVICE
    Account Domain: NT AUTHORITY
    Logon ID: 0x3E5

    Cryptographic Parameters:
    Provider Name: Microsoft Software Key Storage Provider
    Algorithm Name: UNKNOWN
    Key Name: 0c405d387aba56ba
    Key Type: User key.

    Cryptographic Operation:
    Operation: Open Key.
    Return Code: 0x80090016
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>5061</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>12290</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2019-04-28T16:26:51.704606400Z" />
    <EventRecordID>19552</EventRecordID>
    <Correlation />
    <Execution ProcessID="880" ThreadID="1004" />
    <Channel>Security</Channel>
    <Computer>DESKTOP-3#####N</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="SubjectUserSid">S-1-5-19</Data>
    <Data Name="SubjectUserName">LOCAL SERVICE</Data>
    <Data Name="SubjectDomainName">NT AUTHORITY</Data>
    <Data Name="SubjectLogonId">0x3e5</Data>
    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
    <Data Name="AlgorithmName">UNKNOWN</Data>
    <Data Name="KeyName">0c405d387aba56ba</Data>
    <Data Name="KeyType">%%2500</Data>
    <Data Name="Operation">%%2480</Data>
    <Data Name="ReturnCode">0x80090016</Data>
    </EventData>
    </Event>


    THIRD OF FIVE:

    Log Name: Security
    Source: Microsoft-Windows-Security-Auditing
    Date: 4/28/2019 11:29:28 AM
    Event ID: 5061
    Task Category: System Integrity
    Level: Information
    Keywords: Audit Failure
    User: N/A
    Computer: DESKTOP-3#####N
    Description:
    Cryptographic operation.

    Subject:
    Security ID: DESKTOP-3#####N\[My user name]
    Account Name: [My user name]
    Account Domain: DESKTOP-3#####N
    Logon ID: 0x3EF94

    Cryptographic Parameters:
    Provider Name: Microsoft Software Key Storage Provider
    Algorithm Name: UNKNOWN
    Key Name: Microsoft Connected Devices Platform device certificate
    Key Type: User key.

    Cryptographic Operation:
    Operation: Open Key.
    Return Code: 0x80090016
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>5061</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>12290</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2019-04-28T15:29:28.196237300Z" />
    <EventRecordID>19387</EventRecordID>
    <Correlation />
    <Execution ProcessID="884" ThreadID="928" />
    <Channel>Security</Channel>
    <Computer>DESKTOP-3#####N</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="SubjectUserSid">S-1-5-21-3591163430-416291016-3566129944-1001</Data>
    <Data Name="SubjectUserName">[My user name]</Data>
    <Data Name="SubjectDomainName">DESKTOP-3#####N</Data>
    <Data Name="SubjectLogonId">0x3ef94</Data>
    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
    <Data Name="AlgorithmName">UNKNOWN</Data>
    <Data Name="KeyName">Microsoft Connected Devices Platform device certificate</Data>
    <Data Name="KeyType">%%2500</Data>
    <Data Name="Operation">%%2480</Data>
    <Data Name="ReturnCode">0x80090016</Data>
    </EventData>
    </Event>


    SECOND OF FIVE:

    Log Name: Security
    Source: Microsoft-Windows-Security-Auditing
    Date: 4/28/2019 11:28:27 AM
    Event ID: 5061
    Task Category: System Integrity
    Level: Information
    Keywords: Audit Failure
    User: N/A
    Computer: DESKTOP-3#####N
    Description:
    Cryptographic operation.

    Subject:
    Security ID: LOCAL SERVICE
    Account Name: LOCAL SERVICE
    Account Domain: NT AUTHORITY
    Logon ID: 0x3E5

    Cryptographic Parameters:
    Provider Name: Microsoft Software Key Storage Provider
    Algorithm Name: UNKNOWN
    Key Name: 0c405d387aba56ba
    Key Type: User key.

    Cryptographic Operation:
    Operation: Open Key.
    Return Code: 0x80090016
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>5061</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>12290</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2019-04-28T15:28:27.709849300Z" />
    <EventRecordID>19363</EventRecordID>
    <Correlation />
    <Execution ProcessID="884" ThreadID="992" />
    <Channel>Security</Channel>
    <Computer>DESKTOP-3#####N</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="SubjectUserSid">S-1-5-19</Data>
    <Data Name="SubjectUserName">LOCAL SERVICE</Data>
    <Data Name="SubjectDomainName">NT AUTHORITY</Data>
    <Data Name="SubjectLogonId">0x3e5</Data>
    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
    <Data Name="AlgorithmName">UNKNOWN</Data>
    <Data Name="KeyName">0c405d387aba56ba</Data>
    <Data Name="KeyType">%%2500</Data>
    <Data Name="Operation">%%2480</Data>
    <Data Name="ReturnCode">0x80090016</Data>
    </EventData>
    </Event>


    FIRST OF FIVE:

    Log Name: Security
    Source: Microsoft-Windows-Security-Auditing
    Date: 4/28/2019 11:28:27 AM
    Event ID: 5061
    Task Category: System Integrity
    Level: Information
    Keywords: Audit Failure
    User: N/A
    Computer: DESKTOP-3#####N
    Description:
    Cryptographic operation.

    Subject:
    Security ID: LOCAL SERVICE
    Account Name: LOCAL SERVICE
    Account Domain: NT AUTHORITY
    Logon ID: 0x3E5

    Cryptographic Parameters:
    Provider Name: Microsoft Software Key Storage Provider
    Algorithm Name: UNKNOWN
    Key Name: 0c405d387aba56ba
    Key Type: User key.

    Cryptographic Operation:
    Operation: Open Key.
    Return Code: 0x80090016
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>5061</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>12290</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2019-04-28T15:28:27.709849300Z" />
    <EventRecordID>19363</EventRecordID>
    <Correlation />
    <Execution ProcessID="884" ThreadID="992" />
    <Channel>Security</Channel>
    <Computer>DESKTOP-3#####N</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="SubjectUserSid">S-1-5-19</Data>
    <Data Name="SubjectUserName">LOCAL SERVICE</Data>
    <Data Name="SubjectDomainName">NT AUTHORITY</Data>
    <Data Name="SubjectLogonId">0x3e5</Data>
    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
    <Data Name="AlgorithmName">UNKNOWN</Data>
    <Data Name="KeyName">0c405d387aba56ba</Data>
    <Data Name="KeyType">%%2500</Data>
    <Data Name="Operation">%%2480</Data>
    <Data Name="ReturnCode">0x80090016</Data>
    </EventData>
    </Event>


    So, what the *** are these, and how do we fix? No guesses - just the real fix.



    glnzglnz
    ☺ In the office, Dell Optiplex 7040 with 8GB RAM, Win 7 Pro 64-bit and Office 2010
    ☻ At home, Dell Optiplex 7010 with 16GB RAM dual-booting Win 7 Pro 64-bit (now with Office 365 Home) and Win 10 Pro 64-bit
    ♥ Also still have Dell Optiplex 755 with 4GB RAM with Win XP Pro SP3 (which still gets updates with the POS hack) and Office 2003

    :)
     
    glnzglnz, Apr 28, 2019
    #1
  2. danwhocan Win User

    Security Audit Failure Event 5061 In Windows 10

    I'm seeing these in my event log too. The failures happen four seconds before my video driver crashes (and restarts) while playing World of Warcraft. Could these two issues be related? I'm using onboard Intel HD 4600.

    Audit Failure | Microsoft Windows security auditing.
    | 5061 | System Integrity

    Cryptographic operation.

    Subject:

    Security ID: SYSTEM

    Account Name: XXXXXX$

    Account Domain: WORKGROUP

    Logon ID: 0x3E7

    Cryptographic Parameters:

    Provider Name: Microsoft Software Key Storage Provider

    Algorithm Name: RSA

    Key Name: 51a92691-66f1-280f-d0db-59fad4f73491

    Key Type: User key.

    Cryptographic Operation:

    Operation: Open Key.

    Return Code: 0x80090016
     
    danwhocan, Apr 28, 2019
    #2
  3. hellyale Win User
    Audit failure 5061 after logging in to Windows 10

    Logging in to Windows 10 Build 10547 I see for a split second a message box pop up.

    There's no time to read it as the login succeeds.

    In the event log I see:

    It says the key type is a user key.

    Inside the 5061 Audit failure is the following information:

    The details tab contains

    What is going on, and how do I fix it?
     
    hellyale, Apr 28, 2019
    #3
  4. DrSysop Win User

    Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit

    Audit Failure 5061


    I keep getting this Audit failure 5061.

    Cryptographic operation.


    Subject:
    Security ID: SYSTEM
    Account Name: DOCOMO$
    Account Domain: WORKGROUP
    Logon ID: 0x3E7


    Cryptographic Parameters:
    Provider Name: Microsoft Software Key Storage Provider
    Algorithm Name: RSA
    Key Name: 51a92691-66f1-280f-d0db-59fad4f73491
    Key Type: User key.


    Cryptographic Operation:
    Operation: Open Key.
    Return Code: 0x80090016

    I reinstalled my AVG thinking it was that & wasn't same for my Realtek & nvidia drivers & not it. I click on the
    Event Online Help & there is no info on this error.
     
    DrSysop, Apr 28, 2019
    #4
Thema:

Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit

Loading...
  1. Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit - Similar Threads - Audit failures every

  2. Event 5061 - Cryptographic Operation. Windows 11 Pro 22H2 22621.2134 WFEP 1000.22659.100.0

    in Windows 10 Gaming
    Event 5061 - Cryptographic Operation. Windows 11 Pro 22H2 22621.2134 WFEP 1000.22659.100.0: Above is a Screen Shot of the Event ID 5061 and my System Info. Occurs on every reboot. LSASS I'm aware there is another post about this, however, it has been closed and there was never a real resolution from what I could see other than they were on build 1803 and went to...
  3. Event 5061 - Cryptographic Operation. Windows 11 Pro 22H2 22621.2134 WFEP 1000.22659.100.0

    in Windows 10 Software and Apps
    Event 5061 - Cryptographic Operation. Windows 11 Pro 22H2 22621.2134 WFEP 1000.22659.100.0: Above is a Screen Shot of the Event ID 5061 and my System Info. Occurs on every reboot. LSASS I'm aware there is another post about this, however, it has been closed and there was never a real resolution from what I could see other than they were on build 1803 and went to...
  4. Security Audit Failure Event 5061 In Win10 after every browser history deletion

    in AntiVirus, Firewalls and System Security
    Security Audit Failure Event 5061 In Win10 after every browser history deletion: Security Audit Failure Event 5061 In Win10 after every browser history deletion This event is ONLY occurring after clearing the IE11 and Edge browser history i.e cookies, data files, etc., Is any one else by any chance having this issue ? This event appears to be...
  5. Audit failures every reboot - Event 5061 - Cryptographic operation.

    in Windows 10 Support
    Audit failures every reboot - Event 5061 - Cryptographic operation.: Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit version 1803. ‎4/‎28/‎2019 Immediately after every reboot of Win 10 Pro 64-bit version 1803, in Event Viewer, there are between two and four Audit Failures for something related to...
  6. Event ID 5061 Audit Failure after April Update.

    in Windows 10 Support
    Event ID 5061 Audit Failure after April Update.: Okay so this morning I began getting these messages in my event viewer after my PC decided to update to April update. They seem to happen after reboot and boot up. Also trying to updated Defender definitions is kinda not happening. I even tried through cmd line and it said...
  7. Repeating errors in Event Viewer on reboot - Win 10 Pro 64-bit

    in Windows 10 BSOD Crashes and Debugging
    Repeating errors in Event Viewer on reboot - Win 10 Pro 64-bit: I'm getting certain repeating errors in Event Viewer when I reboot my new Win Pro 64-bit (after yesterday's upgrade from Win 8.1 Pro 64-bit). Please see the details and post your thoughts here: https://www.tenforums.com/general-dis...tml#post300970 Thanks. 10425
  8. Audit Failure 5061

    in Windows 10 Support
    Audit Failure 5061: I keep getting this Audit failure 5061. Cryptographic operation. Subject: Security ID: SYSTEM Account Name: DOCOMO$ Account Domain: WORKGROUP Logon ID: 0x3E7 Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name:...
  9. Event ID 5061 Audit Failure after April Update.

    in Windows 10 Support
    Event ID 5061 Audit Failure after April Update.: Not surprised. Let MS fix it. I wonder if people who did a clean install have the issue? Since the certutil command says " Private key is NOT exportable " it may be an issue for those who updated? I myself updated. Well like I said my PC decided to update to April update....
  10. Event Viewer -- Audit Failure 5061

    in Windows 10 Performance & Maintenance
    Event Viewer -- Audit Failure 5061: I continue to get this event in the Event Log under Audit Failure. I never had in Windows 8.1 and it started after upgrading to 10. Does anyone have a clue about it? Cryptographic operation. Subject: Security ID: SYSTEM Account Name: xxxx Account Domain: xxxx...

Users found this page by searching for:

  1. c:\ProgramData\MICROSOFT\CRYPTO\SystemKeys event

    ,
  2. Event ID: 5061 Microsoft-Windows-Security-Auditing Guid={54849625-5478-4994-A5BA-3E3B0328C30D}