Share via


Event ID 10520 — Federation Service Auditing

Applies To: Windows Server 2008

The Federation Service uses auditing to record success and failure audits, such as audits that are written when tokens are created and received.

Event Details

Product: Windows Operating System
ID: 10520
Source: Microsoft-Windows-ADFS
Version: 6.0
Symbolic Name: FS_AUDIT_TOKEN_DETAILS_OutCookie
Message: Transaction ID: %1

This event contains the details of the output logon accelerator token that was issued as part of the referenced transaction.

Token ID: %2
Issuer: %3
Audience: %4
Effective time: %5 %6
Expiration time: %7 %8
Claim source: %9
Authentication methods:
Method%t%tTime
%10
UPN: %11
E-mail: %12
Common name: %13
Groups: (%14 sensitive values omitted)
%15
Custom claims:
Name%t%tValue
%16
SIDs:
%17

Resolve

This is a normal condition. No further action is required.

Federation Service Auditing

Active Directory Federation Services