Event ID: 1000

Applies To: Forefront Endpoint Protection

Event ID 1000 — Forefront Endpoint Protection Client

This event is logged in the Application log.

Details

Product

Microsoft Security Client

ID

1000

Source

Microsoft Security Client

Version

2.0

Symbolic Name

MSG_POLICY_APPLY_SUCCESS

Message

Forefront Endpoint Protection client successfully applied security policy: <Policy Name>.

Explanation

Under normal operating conditions, this event is logged in the Application log every 24 hours. The Forefront Endpoint Protection client logs this success message any time that a policy is applied successfully. Confirm that the policy was intentionally applied to your computer.

User Action

To troubleshoot this event, use one of the following steps:

  • Check the name of the policy as reported in the event and confirm that you intentionally applied the policy. To view and confirm policy settings, in the System Center Configuration Manager console, expand the tree to Computer Configuration, expand Administrative Templates, and then expand Extra Registry Settings to view all policies that are being applied to the computer.

  • You can also right-click the computer in the Forefront Endpoint Protection dashboard, click Properties, and then click Advertisements to see which policies are being applied.

    Then, in Configuration Manager, look at the policy precedence to verify the hierarchy of policies that are being applied.