Event ID 10530 — Federation Service Auditing

Applies To: Windows Server 2008 R2

The Federation Service uses auditing to record success and failure audits, such as audits that are written when tokens are created and received.

Event Details

Product: Windows Operating System
ID: 10530
Source: Microsoft-Windows-ADFS
Version: 6.1
Symbolic Name: FS_AUDIT_TOKEN_DETAILS_InCookie
Message: Transaction ID: %1

This event contains the details of the input logon accelerator token that was received as part of the referenced transaction.

Token ID: %2
Issuer: %3
Audience: %4
Effective time: %5 %6
Expiration time: %7 %8
Claim source: %9
Authentication methods:
Method%t%tTime
%10
UPN: %11
E-mail: %12
Common name: %13
Groups: (%14 sensitive values omitted)
%15
Custom claims:
Name%t%tValue
%16
SIDs:
%17

Resolve

This is a normal condition. No further action is required.

Federation Service Auditing

Active Directory Federation Services