Windows 10: Audit failures every reboot - Event 5061 - Cryptographic operation.

Discus and support Audit failures every reboot - Event 5061 - Cryptographic operation. in Windows 10 Support to solve the problem; Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit version 1803. ‎4/‎28/‎2019 Immediately after every reboot of Win... Discussion in 'Windows 10 Support' started by glnz, Apr 28, 2019.

  1. glnz Win User

    Audit failures every reboot - Event 5061 - Cryptographic operation.


    Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit version 1803. ‎4/‎28/‎2019

    Immediately after every reboot of Win 10 Pro 64-bit version 1803, in Event Viewer, there are between two and four Audit Failures for something related to Cryptography. So my Win 10 machine is insecure? I have run sfc /scannow and Dism /Online /Cleanup-Image /RestoreHealth many times, with no luck. And I hardly even use my Win 10 machine - there are almost no apps on it yet. My actual Win 10 build is 17134.706

    Here are the latest five Cryptography-related Audit Failures, from two reboots:

    LATEST OF FIVE:
    Log Name: Security
    Source: Microsoft-Windows-Security-Auditing
    Date: 4/28/2019 12:27:52 PM
    Event ID: 5061
    Task Category: System Integrity
    Level: Information
    Keywords: Audit Failure
    User: N/A
    Computer: DESKTOP-3#####N
    Description:
    Cryptographic operation.

    Subject:
    Security ID: DESKTOP-3#####N\[My user name]
    Account Name: [My user name]
    Account Domain: DESKTOP-3#####N
    Logon ID: 0x3EC24

    Cryptographic Parameters:
    Provider Name: Microsoft Software Key Storage Provider
    Algorithm Name: UNKNOWN
    Key Name: Microsoft Connected Devices Platform device certificate
    Key Type: User key.

    Cryptographic Operation:
    Operation: Open Key.
    Return Code: 0x80090016
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>5061</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>12290</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2019-04-28T16:27:52.339705400Z" />
    <EventRecordID>19582</EventRecordID>
    <Correlation />
    <Execution ProcessID="880" ThreadID="948" />
    <Channel>Security</Channel>
    <Computer>DESKTOP-3#####N</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="SubjectUserSid">S-1-5-21-3591163430-416291016-3566129944-1001</Data>
    <Data Name="SubjectUserName">[My user name]</Data>
    <Data Name="SubjectDomainName">DESKTOP-3#####N</Data>
    <Data Name="SubjectLogonId">0x3ec24</Data>
    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
    <Data Name="AlgorithmName">UNKNOWN</Data>
    <Data Name="KeyName">Microsoft Connected Devices Platform device certificate</Data>
    <Data Name="KeyType">%%2500</Data>
    <Data Name="Operation">%%2480</Data>
    <Data Name="ReturnCode">0x80090016</Data>
    </EventData>
    </Event>

    FOURTH OF FIVE:
    Log Name: Security
    Source: Microsoft-Windows-Security-Auditing
    Date: 4/28/2019 12:26:51 PM
    Event ID: 5061
    Task Category: System Integrity
    Level: Information
    Keywords: Audit Failure
    User: N/A
    Computer: DESKTOP-3#####N
    Description:
    Cryptographic operation.

    Subject:
    Security ID: LOCAL SERVICE
    Account Name: LOCAL SERVICE
    Account Domain: NT AUTHORITY
    Logon ID: 0x3E5

    Cryptographic Parameters:
    Provider Name: Microsoft Software Key Storage Provider
    Algorithm Name: UNKNOWN
    Key Name: 0c405d387aba56ba
    Key Type: User key.

    Cryptographic Operation:
    Operation: Open Key.
    Return Code: 0x80090016
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>5061</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>12290</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2019-04-28T16:26:51.704606400Z" />
    <EventRecordID>19552</EventRecordID>
    <Correlation />
    <Execution ProcessID="880" ThreadID="1004" />
    <Channel>Security</Channel>
    <Computer>DESKTOP-3#####N</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="SubjectUserSid">S-1-5-19</Data>
    <Data Name="SubjectUserName">LOCAL SERVICE</Data>
    <Data Name="SubjectDomainName">NT AUTHORITY</Data>
    <Data Name="SubjectLogonId">0x3e5</Data>
    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
    <Data Name="AlgorithmName">UNKNOWN</Data>
    <Data Name="KeyName">0c405d387aba56ba</Data>
    <Data Name="KeyType">%%2500</Data>
    <Data Name="Operation">%%2480</Data>
    <Data Name="ReturnCode">0x80090016</Data>
    </EventData>
    </Event>

    THIRD OF FIVE:
    Log Name: Security
    Source: Microsoft-Windows-Security-Auditing
    Date: 4/28/2019 11:29:28 AM
    Event ID: 5061
    Task Category: System Integrity
    Level: Information
    Keywords: Audit Failure
    User: N/A
    Computer: DESKTOP-3#####N
    Description:
    Cryptographic operation.

    Subject:
    Security ID: DESKTOP-3#####N\[My user name]
    Account Name: [My user name]
    Account Domain: DESKTOP-3#####N
    Logon ID: 0x3EF94

    Cryptographic Parameters:
    Provider Name: Microsoft Software Key Storage Provider
    Algorithm Name: UNKNOWN
    Key Name: Microsoft Connected Devices Platform device certificate
    Key Type: User key.

    Cryptographic Operation:
    Operation: Open Key.
    Return Code: 0x80090016
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>5061</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>12290</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2019-04-28T15:29:28.196237300Z" />
    <EventRecordID>19387</EventRecordID>
    <Correlation />
    <Execution ProcessID="884" ThreadID="928" />
    <Channel>Security</Channel>
    <Computer>DESKTOP-3#####N</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="SubjectUserSid">S-1-5-21-3591163430-416291016-3566129944-1001</Data>
    <Data Name="SubjectUserName">[My user name]</Data>
    <Data Name="SubjectDomainName">DESKTOP-3#####N</Data>
    <Data Name="SubjectLogonId">0x3ef94</Data>
    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
    <Data Name="AlgorithmName">UNKNOWN</Data>
    <Data Name="KeyName">Microsoft Connected Devices Platform device certificate</Data>
    <Data Name="KeyType">%%2500</Data>
    <Data Name="Operation">%%2480</Data>
    <Data Name="ReturnCode">0x80090016</Data>
    </EventData>
    </Event>

    SECOND OF FIVE:
    Log Name: Security
    Source: Microsoft-Windows-Security-Auditing
    Date: 4/28/2019 11:28:27 AM
    Event ID: 5061
    Task Category: System Integrity
    Level: Information
    Keywords: Audit Failure
    User: N/A
    Computer: DESKTOP-3#####N
    Description:
    Cryptographic operation.

    Subject:
    Security ID: LOCAL SERVICE
    Account Name: LOCAL SERVICE
    Account Domain: NT AUTHORITY
    Logon ID: 0x3E5

    Cryptographic Parameters:
    Provider Name: Microsoft Software Key Storage Provider
    Algorithm Name: UNKNOWN
    Key Name: 0c405d387aba56ba
    Key Type: User key.

    Cryptographic Operation:
    Operation: Open Key.
    Return Code: 0x80090016
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>5061</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>12290</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2019-04-28T15:28:27.709849300Z" />
    <EventRecordID>19363</EventRecordID>
    <Correlation />
    <Execution ProcessID="884" ThreadID="992" />
    <Channel>Security</Channel>
    <Computer>DESKTOP-3#####N</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="SubjectUserSid">S-1-5-19</Data>
    <Data Name="SubjectUserName">LOCAL SERVICE</Data>
    <Data Name="SubjectDomainName">NT AUTHORITY</Data>
    <Data Name="SubjectLogonId">0x3e5</Data>
    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
    <Data Name="AlgorithmName">UNKNOWN</Data>
    <Data Name="KeyName">0c405d387aba56ba</Data>
    <Data Name="KeyType">%%2500</Data>
    <Data Name="Operation">%%2480</Data>
    <Data Name="ReturnCode">0x80090016</Data>
    </EventData>
    </Event>

    FIRST OF FIVE:
    Log Name: Security
    Source: Microsoft-Windows-Security-Auditing
    Date: 4/28/2019 11:28:27 AM
    Event ID: 5061
    Task Category: System Integrity
    Level: Information
    Keywords: Audit Failure
    User: N/A
    Computer: DESKTOP-3#####N
    Description:
    Cryptographic operation.

    Subject:
    Security ID: LOCAL SERVICE
    Account Name: LOCAL SERVICE
    Account Domain: NT AUTHORITY
    Logon ID: 0x3E5

    Cryptographic Parameters:
    Provider Name: Microsoft Software Key Storage Provider
    Algorithm Name: UNKNOWN
    Key Name: 0c405d387aba56ba
    Key Type: User key.

    Cryptographic Operation:
    Operation: Open Key.
    Return Code: 0x80090016
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>5061</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>12290</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2019-04-28T15:28:27.709849300Z" />
    <EventRecordID>19363</EventRecordID>
    <Correlation />
    <Execution ProcessID="884" ThreadID="992" />
    <Channel>Security</Channel>
    <Computer>DESKTOP-3#####N</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="SubjectUserSid">S-1-5-19</Data>
    <Data Name="SubjectUserName">LOCAL SERVICE</Data>
    <Data Name="SubjectDomainName">NT AUTHORITY</Data>
    <Data Name="SubjectLogonId">0x3e5</Data>
    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
    <Data Name="AlgorithmName">UNKNOWN</Data>
    <Data Name="KeyName">0c405d387aba56ba</Data>
    <Data Name="KeyType">%%2500</Data>
    <Data Name="Operation">%%2480</Data>
    <Data Name="ReturnCode">0x80090016</Data>
    </EventData>
    </Event>
    So, what the *** are these, and how do we fix? No guesses - just the real fix.

    Thanks.

    :)
     
  2. danwhocan Win User

    Security Audit Failure Event 5061 In Windows 10

    I'm seeing these in my event log too. The failures happen four seconds before my video driver crashes (and restarts) while playing World of Warcraft. Could these two issues be related? I'm using onboard Intel HD 4600.

    Audit Failure | Microsoft Windows security auditing.
    | 5061 | System Integrity

    Cryptographic operation.

    Subject:

    Security ID: SYSTEM

    Account Name: XXXXXX$

    Account Domain: WORKGROUP

    Logon ID: 0x3E7

    Cryptographic Parameters:

    Provider Name: Microsoft Software Key Storage Provider

    Algorithm Name: RSA

    Key Name: 51a92691-66f1-280f-d0db-59fad4f73491

    Key Type: User key.

    Cryptographic Operation:

    Operation: Open Key.

    Return Code: 0x80090016
     
    danwhocan, Apr 28, 2019
    #2
  3. DrSysop Win User
    Audit Failure 5061


    I keep getting this Audit failure 5061.

    Cryptographic operation.


    Subject:
    Security ID: SYSTEM
    Account Name: DOCOMO$
    Account Domain: WORKGROUP
    Logon ID: 0x3E7


    Cryptographic Parameters:
    Provider Name: Microsoft Software Key Storage Provider
    Algorithm Name: RSA
    Key Name: 51a92691-66f1-280f-d0db-59fad4f73491
    Key Type: User key.


    Cryptographic Operation:
    Operation: Open Key.
    Return Code: 0x80090016

    I reinstalled my AVG thinking it was that & wasn't same for my Realtek & nvidia drivers & not it. I click on the
    Event Online Help & there is no info on this error.
     
    DrSysop, Apr 28, 2019
    #3
  4. balittle Win User

    Audit failures every reboot - Event 5061 - Cryptographic operation.

    event 5061, microsoft windows security auditing failure

    event 5061, microsoft windows security auditing failure

    Have no idea how to fix, but its provided by Microsoft and an unknown alogorithm name?
     
    balittle, Apr 28, 2019
    #4
Thema:

Audit failures every reboot - Event 5061 - Cryptographic operation.

Loading...
  1. Audit failures every reboot - Event 5061 - Cryptographic operation. - Similar Threads - Audit failures every

  2. Event 5061 - Cryptographic Operation. Windows 11 Pro 22H2 22621.2134 WFEP 1000.22659.100.0

    in Windows 10 Gaming
    Event 5061 - Cryptographic Operation. Windows 11 Pro 22H2 22621.2134 WFEP 1000.22659.100.0: Above is a Screen Shot of the Event ID 5061 and my System Info. Occurs on every reboot. LSASS I'm aware there is another post about this, however, it has been closed and there was never a real resolution from what I could see other than they were on build 1803 and went to...
  3. Event 5061 - Cryptographic Operation. Windows 11 Pro 22H2 22621.2134 WFEP 1000.22659.100.0

    in Windows 10 Software and Apps
    Event 5061 - Cryptographic Operation. Windows 11 Pro 22H2 22621.2134 WFEP 1000.22659.100.0: Above is a Screen Shot of the Event ID 5061 and my System Info. Occurs on every reboot. LSASS I'm aware there is another post about this, however, it has been closed and there was never a real resolution from what I could see other than they were on build 1803 and went to...
  4. Keyboard stops working every time, there is an auditing failure error 5061, can't seem to...

    in Windows 10 Drivers and Hardware
    Keyboard stops working every time, there is an auditing failure error 5061, can't seem to...: My keyboard has been randomly stopping since a few weeks ago, at first it was nothing big as i could simply just reconnect it. But the problem kept continuing, and occasionally reconnecting doesn't work, and my mouse stops working together with the keyboard, and i have to...
  5. Security Audit Failure Event 5061 In Win10 after every browser history deletion

    in AntiVirus, Firewalls and System Security
    Security Audit Failure Event 5061 In Win10 after every browser history deletion: Security Audit Failure Event 5061 In Win10 after every browser history deletion This event is ONLY occurring after clearing the IE11 and Edge browser history i.e cookies, data files, etc., Is any one else by any chance having this issue ? This event appears to be...
  6. Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit

    in Windows 10 BSOD Crashes and Debugging
    Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit: Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit version 1803. ‎4/‎28/‎2019 Immediately after every reboot of Win 10 Pro 64-bit version 1803, in Event Viewer, there are between two and four Audit Failures for something related to...
  7. Event ID 5061 Audit Failure after April Update.

    in Windows 10 Support
    Event ID 5061 Audit Failure after April Update.: Okay so this morning I began getting these messages in my event viewer after my PC decided to update to April update. They seem to happen after reboot and boot up. Also trying to updated Defender definitions is kinda not happening. I even tried through cmd line and it said...
  8. Audit Failure 5061

    in Windows 10 Support
    Audit Failure 5061: I keep getting this Audit failure 5061. Cryptographic operation. Subject: Security ID: SYSTEM Account Name: DOCOMO$ Account Domain: WORKGROUP Logon ID: 0x3E7 Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name:...
  9. Event ID 5061 Audit Failure after April Update.

    in Windows 10 Support
    Event ID 5061 Audit Failure after April Update.: Not surprised. Let MS fix it. I wonder if people who did a clean install have the issue? Since the certutil command says " Private key is NOT exportable " it may be an issue for those who updated? I myself updated. Well like I said my PC decided to update to April update....
  10. Event Viewer -- Audit Failure 5061

    in Windows 10 Performance & Maintenance
    Event Viewer -- Audit Failure 5061: I continue to get this event in the Event Log under Audit Failure. I never had in Windows 8.1 and it started after upgrading to 10. Does anyone have a clue about it? Cryptographic operation. Subject: Security ID: SYSTEM Account Name: xxxx Account Domain: xxxx...