﻿<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v3" manifestVersion="1.0" copyright="Copyright (c) Microsoft Corporation. All Rights Reserved.">
  <assemblyIdentity name="Microsoft-Windows-Directory-Services-SAM" version="10.0.10586.306" processorArchitecture="amd64" language="neutral" buildType="release" publicKeyToken="31bf3856ad364e35" versionScope="nonSxS" />
  <dependency discoverable="no" resourceType="resources">
    <dependentAssembly>
      <assemblyIdentity name="Microsoft-Windows-Directory-Services-SAM.Resources" version="10.0.10586.306" processorArchitecture="amd64" language="*" buildType="release" publicKeyToken="31bf3856ad364e35" />
    </dependentAssembly>
  </dependency>
  <file name="samsrv.dll" destinationPath="$(runtime.system32)\" sourceName="samsrv.dll" sourcePath=".\" importPath="$(build.nttree)\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <signatureInfo xmlns="urn:schemas-microsoft-com:asm.v3">
      <signatureDescriptor PETrust="true" />
    </signatureInfo>
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2">
      <dsig:Transforms xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">Lj/XgwCiM6I0mtT47/Wb7wux26s8WkFL+RFzi58GNXA=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <file name="samlib.dll" destinationPath="$(runtime.system32)\" sourceName="samlib.dll" sourcePath=".\" importPath="$(build.nttree)\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <signatureInfo xmlns="urn:schemas-microsoft-com:asm.v3">
      <signatureDescriptor PETrust="true" pageHash="true" />
    </signatureInfo>
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2">
      <dsig:Transforms xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">DIW/Pj5AtzfHB0zJEWMReToxsBklzns9GyqDfBHC9iI=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <file name="offlinesam.dll" destinationPath="$(runtime.system32)\" sourceName="offlinesam.dll" sourcePath=".\" importPath="$(build.nttree)\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2">
      <dsig:Transforms xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">eqgQBTXSbXAQQ8wrR2d0poyJrpgi9M3Ub6uvprswHBg=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <memberships>
    <categoryMembership>
      <id name="Microsoft.Windows.Categories" version="1.0.0.0" publicKeyToken="365143bb27e7ac8b" typeName="BootRecovery" />
    </categoryMembership>
    <categoryMembership>
      <id name="Microsoft.Windows.Categories" version="1.0.0.0" publicKeyToken="365143bb27e7ac8b" typeName="Service" />
      <categoryInstance>
        <serviceData name="SamSs" displayName="@%SystemRoot%\system32\samsrv.dll,-1" errorControl="normal" group="MS_WindowsLocalValidation" imagePath="%SystemRoot%\system32\lsass.exe" start="auto" type="win32ShareProcess" description="@%SystemRoot%\system32\samsrv.dll,-2" dependOnService="RPCSS" objectName="LocalSystem" />
      </categoryInstance>
    </categoryMembership>
  </memberships>
  <registryKeys>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SamSs">
      <securityDescriptor name="ServiceSamSSKeySecurity" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SamSs\Security">
      <registryValue name="Security" valueType="REG_BINARY" value="01001480900000009C000000140000003000000002001C000100000002801400FF010F000101000000000001000000000200600004000000000014008D00020001010000000000050B00000000001800FF010F0001020000000000052000000020020000000014008D000000010100000000000504000000000018008D00000001020000000000052000000021020000010100000000000512000000010100000000000512000000" />
      <securityDescriptor name="ServiceSamSSKeySecurity" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\Setup\AllowStart\SamSs">
      <securityDescriptor name="ServiceSamSSKeySecurity" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\SAM">
      <registryValue name="EventMessageFile" valueType="REG_EXPAND_SZ" value="%SystemRoot%\System32\samsrv.dll" />
      <registryValue name="TypesSupported" valueType="REG_DWORD" value="0x00000007" />
      <registryValue name="providerGuid" valueType="REG_SZ" value="{0D4FDC09-8C27-494A-BDA0-505E4FD8ADAE}" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MUI\CallbackDlls\RefreshSAM">
      <registryValue name="Type" valueType="REG_DWORD" value="0x00000108" />
      <registryValue name="DllPath" valueType="REG_EXPAND_SZ" value="%SystemRoot%\System32\samlib.dll" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ManufacturingMode\Default\Services\SamSs">
      <registryValue name="Start" valueType="REG_DWORD" value="0x00000002" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
  </registryKeys>
  <trustInfo>
    <security>
      <accessControl>
        <securityDescriptorDefinitions>
          <securityDescriptorDefinition name="ServiceSamSSKeySecurity" sddl="O:BAG:BAD:P(A;CI;GA;;;SY)(A;CI;GRGX;;;BA)(A;CI;GRGX;;;BU)S:(AU;FASA;WDWO;;;BA)" operationHint="replace" />
          <securityDescriptorDefinition name="WRP_FILE_DEFAULT_SDDL" sddl="O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:P(A;;FA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;GRGX;;;BA)(A;;GRGX;;;SY)(A;;GRGX;;;BU)(A;;GRGX;;;S-1-15-2-1)S:(AU;FASA;0x000D0116;;;WD)" operationHint="replace" description="Default SDDL for Windows Resource Protected file" />
          <securityDescriptorDefinition name="WRP_REGKEY_DEFAULT_SDDL" sddl="O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:P(A;CI;GA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;CI;GR;;;SY)(A;CI;GR;;;BA)(A;CI;GR;;;BU)(A;CI;GR;;;S-1-15-2-1)" operationHint="replace" />
        </securityDescriptorDefinitions>
      </accessControl>
    </security>
  </trustInfo>
  <localization>
    <resources culture="en-US">
      <stringTable>
        <string id="config_description_AppletalkClientSupport" value="Control AppleTalk protocol sequence support." />
        <string id="config_description_AvoidPdcOnWan" value="Avoid retry of authentication at PDC if it's not in our site.  Also avoid updating logon statistics at the PDC." />
        <string id="config_description_dsrmAdminLogonBehavior" value="0 - default behavior, DSRM account only allowed to logon in DSRM mode, 1 - DSRM account can logon when DS is stopped or in DSRM, 2 - DSRM account can logon all the time." />
        <string id="config_description_ExtendedSidEmulationMode" value="Until large SID support is supported, applications can put a server in 'Emulation Mode' via a registry key. This causes the SAM server to behave as if the account domain is in ExtendedSid mode but the account doesn't really allocate SID's in a large sid fashion.  This emulation is controlled by the registry key ExtendedSidEmulationMode: a value of 1 indicates compatibility mode 1; a value of 2 indicates compatibility mode 2; any other value is ignored." />
        <string id="config_description_ForceGuest" value="Configures system such that network authentication is always in the Guest account context" />
        <string id="config_description_IgnoreGCFailures" value="Configures system to not fail logons if no GC is present" />
        <string id="config_description_MaxSamConnections" value="The maximum allowable number of active clients." />
        <string id="config_description_NetWareClientSupport" value="Control NetWare protocol sequence support." />
        <string id="config_description_NoLmHash" value="Configures system to not store LM hash of password." />
        <string id="config_description_Notification_Packages" value="List of package module names, without extension, that should be loaded for password change notification callouts" />
        <string id="config_description_ProductType" value="Cached product type ID maintained by SAM" />
        <string id="config_description_RestrictAnonymous" value="0 - Disabled. Anonymous users are not restricted.  1 - Enabled. Users who log on anonymously (also known as null session connections) cannot display lists of domain user names or share names. Also, these users can not view security permissions, and they can not use all of the features of File Explorer, Local Users and Groups, and other programs that enumerate users or shares.  2 - Anonymous users have no access without explicit anonymous permissions." />
        <string id="config_description_RestrictAnonymousSam" value="If enabled requires client to be an authenticated user to get DOMAIN_LIST_ACCOUNTS or GROUP_LIST_MEMBERS or ALIAS_LIST_MEMBERS access." />
        <string id="config_description_RestrictRemoteSam" value="Security Descriptor Definition Language (SDDL) string allows or blocks remote access to the SAM. If the value is missing or incorrect, remote access is allowed. This SDDL does not change the access given to a remote user." />
        <string id="config_description_RID_Block_Size" value="Enables setting RID pool sizes greater than the default 500, commonly used for outward facing directories with high volume account creation and low replica count." />
        <string id="config_description_SamAccountLockoutTestMode" value="Configures system such that bad password count is updated in AD but not the user account control bit to lockout the account." />
        <string id="config_description_SamDisableListenOnTCP" value="Controls whether SAM service listens on TCP." />
        <string id="config_description_SamDisableSingleObjectRepl" value="Configures system to not replication down updated information from the PDC during logon failures" />
        <string id="config_description_SamLogLevel" value="Logging mask to enable SAM diagnostic logging to %windir%\debug\sam.log." />
        <string id="config_description_SamNoGcLogonEnforceKerberosIpCheck" value="Configures system user Kerberos logon information to determine site membership for the no GC logon configuration" />
        <string id="config_description_SamNoGcLogonEnforceNTLMCheck" value="Configures system to user NTLM logon information to determine site membership for the no GC logon configuration." />
        <string id="config_description_SamReplicatePasswordsUrgently" value="Configures system to replicate password deltas urgently within a site" />
        <string id="config_description_SamRestrictOwfPasswordChange" value="0 - old behavior, client can change password through OWF password change API, and the new password remains unexpired.  1 - Windows XP and Windows Server 2003 default behavior, client can change password through OWF password change API (SamrChangePasswordUser), but the password expires immediately.  2 - more secure behavior, client cannot use OWF password change API. This API (SamrChangePasswordUser) will be totally locked down." />
        <string id="config_description_TraceSamEventInDetail" value="Set level of trace detail in SAM trace events." />
        <string id="config_description_VinesClientSupport" value="Control Banyan Vines protocol sequence support." />
        <string id="config_description1" value="Application Channels for SAM" />
        <string id="config_displayName_AppletalkClientSupport" value="AppletalkClientSupport" />
        <string id="config_displayName_AvoidPdcOnWan" value="AvoidPdcOnWan" />
        <string id="config_displayName_dsrmAdminLogonBehavior" value="dsrmAdminLogonBehavior" />
        <string id="config_displayName_ExtendedSidEmulationMode" value="ExtendedSidEmulationMode" />
        <string id="config_displayName_ForceGuest" value="ForceGuest" />
        <string id="config_displayName_IgnoreGCFailures" value="IgnoreGCFailures" />
        <string id="config_displayName_MaxSamConnections" value="MaxSamConnections" />
        <string id="config_displayName_NetWareClientSupport" value="NetWareClientSupport" />
        <string id="config_displayName_NoLmHash" value="NoLmHash" />
        <string id="config_displayName_Notification_Packages" value="Notification Packages" />
        <string id="config_displayName_ProductType" value="ProductType" />
        <string id="config_displayName_RestrictAnonymous" value="RestrictAnonymous" />
        <string id="config_displayName_RestrictAnonymousSam" value="RestrictAnonymousSam" />
        <string id="config_displayName_RestrictRemoteSam" value="RestrictRemoteSam" />
        <string id="config_displayName_RID_Block_Size" value="RID Block Size" />
        <string id="config_displayName_SamAccountLockoutTestMode" value="SamAccountLockoutTestMode" />
        <string id="config_displayName_SamDisableListenOnTCP" value="SamDisableListenOnTCP" />
        <string id="config_displayName_SamDisableSingleObjectRepl" value="SamDisableSingleObjectRepl" />
        <string id="config_displayName_SamLogLevel" value="SamLogLevel" />
        <string id="config_displayName_SamNoGcLogonEnforceKerberosIpCheck" value="SamNoGcLogonEnforceKerberosIpCheck" />
        <string id="config_displayName_SamNoGcLogonEnforceNTLMCheck" value="SamNoGcLogonEnforceNTLMCheck" />
        <string id="config_displayName_SamReplicatePasswordsUrgently" value="SamReplicatePasswordsUrgently" />
        <string id="config_displayName_SamRestrictOwfPasswordChange" value="SamRestrictOwfPasswordChange" />
        <string id="config_displayName_TraceSamEventInDetail" value="TraceSamEventInDetail" />
        <string id="config_displayName_UpdateLastLogonTSByMinute" value="UpdateLastLogonTSByMinute" />
        <string id="config_displayName_VinesClientSupport" value="VinesClientSupport" />
        <string id="config_displayName1" value="SAM Application Channels" />
        <string id="description" value="Manifest compiled into samsrv.dll" />
        <string id="displayName" value="Microsoft-Windows-Directory-Services-SAM" />
        <string id="event_0x3000" value="SAM failed to write changes to the database. This is most likely due to a memory or disk-space shortage. The SAM database will be restored to an earlier state. Recent changes will be lost. Check the disk-space available and maximum pagefile size setting." />
        <string id="event_0x3001" value="SAM failed to restore the database to an earlier state. SAM has shutdown. You must reboot the machine to re-enable SAM." />
        <string id="event_0x3003" value="SAM failed to start the TCP/IP or SPX/IPX listening thread" />
        <string id="event_0x3005" value="There are two or more objects that have the same SID attribute in the SAM database. The Distinguished Name of the account is %1. All duplicate accounts have been deleted. Check the event log for additional duplicates." />
        <string id="event_0x3006" value="The SAM database was unable to lockout the account of %1 due to a resource error, such as a hard disk write failure (the specific error code is in the error data) . Accounts are locked after a certain number of bad passwords are provided so please consider resetting the password of the account mentioned above." />
        <string id="event_0x3007" value="The SAM database attempted to delete the file %1 as it contains account information that is no longer used.  The error is in the record data. Please have an administrator delete this file." />
        <string id="event_0x3008" value="The SAM database attempted to clear the directory %1 in order to remove files that were once used by the Directory Service. The error is in record data. Please have an admin delete these files." />
        <string id="event_0x3009" value="%1 is now the primary domain controller for the domain." />
        <string id="event_0x300A" value="The account %1 cannot be converted to be a domain controller account as its object class attribute in the directory is not computer or is not derived from computer. If this is caused by an attempt to install a pre Windows 2000 domain controller in a Windows 2000 domain or later, then you should pre-create the account for the domain controller with the correct object class." />
        <string id="event_0x300B" value="The attempt to check whether group caching has been enabled in the Security Accounts Manager has failed, most likely due to lack of resources. This task has been rescheduled to run in one minute." />
        <string id="event_0x300C" value="The group caching option in the Security Accounts Manager has now been properly updated.  Group caching is enabled." />
        <string id="event_0x300D" value="The group caching option in the Security Accounts Manager has now been properly updated. Group caching is disabled." />
        <string id="event_0x300E" value="The %1 package failed to update additional credentials for user %2.  The error code is in the data of the event log message." />
        <string id="event_0x300F" value="There are two or more well known objects that have the same SID attribute in the SAM database. The Distinguished Name of the duplicate account is %1. The newest account will be kept, all older duplicate accounts have been deleted. Check the event log for additional duplicates." />
        <string id="event_0x3010" value="There are two or more objects that have the same account name attribute in the SAM database. The system has automatically renamed object %1 to a system assigned account name %2." />
        <string id="event_0x3011" value="An error occurred while creating new default accounts for this domain.  This maybe due to a transient error condition. The task will retry periodically until success and will log this message again in a week if the problem persists." />
        <string id="event_0x4000" value="The account %1 could not be upgraded since there is an account with an equivalent name." />
        <string id="event_0x4001" value="An error occurred upgrading user %1.  This account will have to be added manually upon reboot." />
        <string id="event_0x4002" value="An error occurred trying to read a user object from the old database." />
        <string id="event_0x4003" value="An error occurred upgrading alias %1. This account will have to be added manually upon reboot." />
        <string id="event_0x4004" value="An error occurred trying to read an alias object from the old database." />
        <string id="event_0x4005" value="An error occurred upgrading group %1. This account will have to be added manually upon reboot." />
        <string id="event_0x4006" value="An error occurred trying to read a group object from the old database." />
        <string id="event_0x4007" value="An error occurred trying to add account %1 to alias %2.  This account will have to be added manually upon reboot." />
        <string id="event_0x4008" value="The account with the sid %1 could not be added to group %2." />
        <string id="event_0x4009" value="An error occurred trying to add account %1 to group %2.  This account will have to be added manually upon reboot." />
        <string id="event_0x400A" value="The account with the rid %1 could not be added to group %2." />
        <string id="event_0x400B" value="A fatal error occurred trying to transfer the SAM account database into the directory service. A possible reason is the SAM account database is corrupt." />
        <string id="event_0x400E" value="An error occurred trying to upgrade a SAM user's User_Parameters attribute. The following Notification Package DLL might be the possible offender: %1. Check the record data of this event for the NT error code." />
        <string id="event_0x400F" value="An error occured trying to set User Parameters attribute for this user This operation is failed. Check the record data of this event for the NT error code." />
        <string id="event_0x4010" value="An error occured trying to upgrade the following SAM User Object - %1. We will try to continue upgrading this user. But it might contain inconsistent data. Check the record data of this event for the NT error code." />
        <string id="event_0x4011" value="An error occurred when trying to add the account %1 to the group %2. The problem, &quot;%3&quot;, occurred when trying to open the group. Please add the account manually." />
        <string id="event_0x4012" value="An error occurred when trying to add the account %1 to the group %2. The problem, &quot;%3&quot;, occurred when trying to add the account to the group.  Please add the account manually." />
        <string id="event_0x4013" value="The error &quot;%2&quot; occurred when trying to create the well known account %1. Please contact PSS to recover." />
        <string id="event_0x4015" value="During the installation of the Directory Service, this server's machine account was deleted hence preventing this Domain Controller from starting up." />
        <string id="event_0x4016" value="The Security Account Database detected that the well known account %1 does not exist. The account has been recreated.  Please reset the password for the account." />
        <string id="event_0x4017" value="The Security Account Database detected that the well known group or local group %1 does not exist. The group has been recreated." />
        <string id="event_0x4018" value="Domain operation mode has been changed to Native Mode. The change cannot be reversed." />
        <string id="event_0x4019" value="Active Directory Domain Services failed to add a security principal to well known security principals container. Please have an administrator add this security principal if needed. Security principal name: %1" />
        <string id="event_0x401A" value="Active Directory Domain Services failed to add all of the new security principals to well known security principals container. Please have an administrator add these security principals if needed." />
        <string id="event_0x401B" value="Active Directory Domain Services failed to rename a security principal in well known security principals container. Please have an administrator rename this security principal if needed. Security principal name: %1" />
        <string id="event_0x401C" value="Active Directory Domain Services failed to rename some of the security principals in well known security principals container. Please have an administrator rename these security principals if needed." />
        <string id="event_0x401D" value="An error occurred when trying to remove the account %1 from the group %2. The problem, &quot;%3&quot;, occurred when trying to remove the account from the group.  Please remove the member manually." />
        <string id="event_0x4102" value="The account-identifier allocator was unable to assign a new identifier. The identifier pool for this domain controller may have been depleted. If this problem persists, restart the domain controller and view the initialization status of the allocator in the event log." />
        <string id="event_0x4103" value="An initial account-identifier pool has not yet been allocated to this domain controller. A possible reason for this is that the domain controller has been unable to contact the master domain controller, possibly due to connectivity or network problems. Account creation will fail on this domain controller until the pool is obtained." />
        <string id="event_0x4104" value="The maximum domain account identifier value has been reached. No further account-identifier pools can be allocated to domain controllers in this domain." />
        <string id="event_0x4105" value="The maximum account identifier allocated to this domain controller has been assigned. The domain controller has failed to obtain a new identifier pool. A possible reason for this is that the domain controller has been unable to contact the master domain controller. Account creation on this controller will fail until a new pool has been allocated. There may be network or connectivity problems in the domain, or the master domain controller may be offline or missing from the domain. Verify that the master domain controller is running and connected to the domain." />
        <string id="event_0x4106" value="The computed account identifier is invalid because it is out of the range of the current account-identifier pool belonging to this domain controller. The computed RID value is %1. Try invalidating the account identifier pool owned by this domain controller. This will make the domain controller acquire a fresh account identifier pool." />
        <string id="event_0x4107" value="The domain controller is starting a request for a new account-identifier pool." />
        <string id="event_0x4108" value="The request for a new account-identifier pool has completed successfully." />
        <string id="event_0x4109" value="The account-identifier-manager object creation completed. If the record data for this event has the value zero, the manager object was created. Otherwise, the record data will contain the NT error code indicating the failure. The failure to create the object may be due to low system resources, insufficient memory, or disk space." />
        <string id="event_0x410B" value="The request for a new account-identifier pool failed. The operation will be retried until the request succeeds. The error is %n &quot; %1 &quot;" />
        <string id="event_0x410C" value="The domain controller is booting to directory services restore mode." />
        <string id="event_0x410D" value="A pool size for account-identifiers (RIDs) that was configured by an Administrator is greater than the supported maximum. The maximum value of %1 will be used when the domain controller is the RID master. %nSee http://go.microsoft.com/fwlink/?LinkId=225963 for more information." />
        <string id="event_0x410E" value="A pool of account-identifiers (RIDs) has been invalidated. This may occur in the following expected cases:%n1. A domain controller is restored from backup. %n2. A domain controller running on a virtual machine is restored from snapshot. %n3. An administrator has manually invalidated the pool. %nSee http://go.microsoft.com/fwlink/?LinkId=226247 for more information." />
        <string id="event_0x410F" value="The global maximum for account-identifiers (RIDs) has been increased to %1. %n See http://go.microsoft.com/fwlink/?LinkId=233329 for more information including important operating system interoperability requirements." />
        <string id="event_0x4110" value="Action required! An account-identifier (RID) pool was allocated to this domain controller. The pool value indicates this domain has consumed a considerable portion of the total available account-identifiers. %n%nA protection mechanism will be activated when the domain reaches the following threshold of total available account-identifiers remaining: %1.  The protection mechanism prevents the allocation of account-identifier (RID) pools needed to allow existing DCs to create additional users, computers and groups, or promote new DCs into the domain. The mechanism will remain active until the Administrator manually re-enables account-identifier allocation on the RID master domain controller. %n%nSee http://go.microsoft.com/fwlink/?LinkId=228610 for more information." />
        <string id="event_0x4111" value="Action required! This domain has consumed a considerable portion of the total available account-identifiers (RIDs). A protection mechanism has been activated because the total available account-identifiers remaining is approximately: %1. %n%nThe protection mechanism prevents the allocation of account-identifier (RID) pools needed to allow existing DCs to create additional users, computers and groups, or promote new DCs into the domain.  The mechanism will remain active until the Administrator manually re-enables account-identifier (RID) allocation on the RID master domain controller. %n%nIt is extremely important that certain diagnostics be performed prior to re-enabling account creation to ensure this domain is not consuming account-identifiers at an abnormally high rate. Any issues identified should be resolved prior to re-enabling account creation. %n%nFailure to diagnose and fix any underlying issue causing an abnormally high rate of account-identifier consumption can lead to account-identifier (RID) pool exhaustion in the domain after which account creation will be permanently disabled in this domain. %n%nSee http://go.microsoft.com/fwlink/?LinkId=228610 for more information." />
        <string id="event_0x4112" value="This event is a periodic update on the remaining total quantity of available account-identifiers (RIDs). The number of remaining account-identifiers is approximately: %1. %n%nAccount-identifiers are used as accounts are created, when they are exhausted no new accounts may be created in the domain. %n%nSee http://go.microsoft.com/fwlink/?LinkId=228745 for more information." />
        <string id="event_0x4227" value="Failed to secure the machine account %1.  Have an administrator remove the builtin\account operators full control Access Control Entry from the security descriptor on this object." />
        <string id="event_0x4228" value="Failed to secure the machine account %1.  This operation will be retried. Have an administrator verify the builtin\account operators full control Access Control Entry was removed from the security descriptor on this object." />
        <string id="event_0x4229" value="Secured the machine account %1.  The builtin\account operators full control Access Control Entry was removed from the security descriptor on this object." />
        <string id="event_0x4230" value="The certificate that is used for authentication does not have an issuance policy descriptor corresponding to OID %1 in the Active Directory database. This certificate will not be associated with a corresponding security identifier (SID), and the user may be denied access to some resources if you have resources whose access is restricted based on this issuance policy. The error is %2." />
        <string id="event_0x4231" value="The certificate issuance policy that is represented by OID %2 does not have a link to a security identifier (SID), or this link cannot be read. The link is represented by the attribute msDS-OIDToGroupLink on the msPKI-Enterprise-Oid object that represents the issuance policy. This certificate will not be associated with a corresponding SID, and the user may be denied access to some resources if you have resources whose access is restricted based on this issuance policy." />
        <string id="event_0x4232" value="Multiple certificate issuance policy descriptors were found in the Active Directory database. The attribute msPKI-Cert-Template-OID of these descriptors contains string %1.  This attribute should be able to uniquely identify an issuance policy descriptor; you should resolve this conflict. The issuance policies that are affected will not be associated with security identifiers (SIDs), and users who are authenticating using certificates that are issued by the corresponding policy may be denied access to some resources." />
        <string id="event_0x4233" value="The certificate issuance policy descriptor %2 is linked through its attribute msDS-OIDToGroupLink to a group that is not a security group, has members, or is not universal. The error is %6.%nAn issuance policy should be linked to a security identifier (SID) of a group that is security enabled, does not have members, and is universal. Users who are authenticating using certificates that are issued according to this policy may be denied access to some resources. The distinguished name (also known as DN) of the group that does not meet these requirements is %3." />
        <string id="event_0x4234" value="The requested modification for group %1 could not be performed. This is because this group is linked through msDS-OIDToGroupLinkBl to a certificate issuance policy descriptor. Such groups should be security enabled, they should not have any members, and they should be universal.%nThe requested operation was %4.%nThe error is %5." />
        <string id="event_0x4235" value="The certificate issuance policy descriptor %1 cannot be linked to group %2. Issuance policies can be linked through the attribute msDS-OIDToGroupLink only to universal, security-enabled groups that have an empty membership. You should ensure that this group meets these requirements.%nThe error is %5." />
        <string id="event_0x4236" value="The following invalid claims issued to user %1 have been dropped: %2." />
        <string id="event_0x4237" value="Claims issued to user %1 could not be validated and have been dropped. Error: %2." />
        <string id="event_0x4238" value="Claims issued to user %1 could not be validated and have been dropped. Error: %2." />
        <string id="event_0x4239" value="The password notification DLL %1 failed to load with error %4. Please verify that the notification DLL path defined in the registry, %2%3, refers to a correct and absolute path (&lt;drive&gt;:\&lt;path&gt;\&lt;filename&gt;.&lt;ext&gt;) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898." />
        <string id="event_0x4240" value="SAM was configured to not listen on the TCP protocol." />
        <string id="event_0x4241" value="Legacy password validation mode has been enabled on this machine. If an Exchange ActiveSync policy is configured it will not be enforced for password validation requests." />
        <string id="eventProviderName" value="Microsoft-Windows-Directory-Services-SAM" />
        <string id="msg_0x2000" value="Administrator" />
        <string id="msg_0x2001" value="Guest" />
        <string id="msg_0x2002" value="Domain Admins" />
        <string id="msg_0x2003" value="Domain Users" />
        <string id="msg_0x2004" value="None" />
        <string id="msg_0x2005" value="Administrators" />
        <string id="msg_0x2006" value="Server Operators" />
        <string id="msg_0x2007" value="Power Users" />
        <string id="msg_0x2008" value="Users" />
        <string id="msg_0x2009" value="Guests" />
        <string id="msg_0x200A" value="Account Operators" />
        <string id="msg_0x200B" value="Print Operators" />
        <string id="msg_0x200C" value="Backup Operators" />
        <string id="msg_0x200D" value="Replicator" />
        <string id="msg_0x200E" value="Domain Guests" />
        <string id="msg_0x200F" value="$AccountNameConflict%1" />
        <string id="msg_0x2010" value="krbtgt" />
        <string id="msg_0x2011" value="Domain Computers" />
        <string id="msg_0x2012" value="Domain Controllers" />
        <string id="msg_0x2013" value="Schema Admins" />
        <string id="msg_0x2014" value="Cert Publishers" />
        <string id="msg_0x2015" value="Enterprise Admins" />
        <string id="msg_0x2016" value="RAS and IAS Servers" />
        <string id="msg_0x2017" value="Group Policy Creator Owners" />
        <string id="msg_0x2018" value="Pre-Windows 2000 Compatible Access" />
        <string id="msg_0x2019" value="Everyone" />
        <string id="msg_0x201A" value="Remote Desktop Users" />
        <string id="msg_0x201B" value="Administrators" />
        <string id="msg_0x201C" value="Anonymous Logon" />
        <string id="msg_0x201D" value="Network Configuration Operators" />
        <string id="msg_0x201E" value="Incoming Forest Trust Builders" />
        <string id="msg_0x201F" value="Performance Monitor Users" />
        <string id="msg_0x2020" value="Performance Log Users" />
        <string id="msg_0x2021" value="Windows Authorization Access Group" />
        <string id="msg_0x2022" value="Network Service" />
        <string id="msg_0x2023" value="Enterprise Domain Controllers" />
        <string id="msg_0x2024" value="Terminal Server License Servers" />
        <string id="msg_0x2025" value="Trusted Installers" />
        <string id="msg_0x2026" value="Distributed COM Users" />
        <string id="msg_0x2027" value="IIS_IUSRS" />
        <string id="msg_0x202A" value="Cryptographic Operators" />
        <string id="msg_0x202B" value="INTERNET USER" />
        <string id="msg_0x202D" value="Allowed RODC Password Replication Group" />
        <string id="msg_0x202E" value="Denied RODC Password Replication Group" />
        <string id="msg_0x202F" value="Read-only Domain Controllers" />
        <string id="msg_0x2030" value="Enterprise Read-only Domain Controllers" />
        <string id="msg_0x2031" value="Event Log Readers" />
        <string id="msg_0x2032" value="Certificate Service DCOM Access" />
        <string id="msg_0x2033" value="RDS Remote Access Servers" />
        <string id="msg_0x2034" value="RDS Endpoint Servers" />
        <string id="msg_0x2035" value="RDS Management Servers" />
        <string id="msg_0x2036" value="Hyper-V Administrators" />
        <string id="msg_0x2037" value="Cloneable Domain Controllers" />
        <string id="msg_0x2038" value="Access Control Assistance Operators" />
        <string id="msg_0x2039" value="Remote Management Users" />
        <string id="msg_0x203A" value="DefaultAccount" />
        <string id="msg_0x203B" value="System Managed Accounts Group" />
        <string id="msg_0x2100" value="Built-in account for administering the computer/domain" />
        <string id="msg_0x2101" value="Built-in account for guest access to the computer/domain" />
        <string id="msg_0x2102" value="Designated administrators of the domain" />
        <string id="msg_0x2103" value="All domain users" />
        <string id="msg_0x2104" value="Ordinary users" />
        <string id="msg_0x2105" value="Administrators have complete and unrestricted access to the computer/domain" />
        <string id="msg_0x2106" value="Members can administer domain servers" />
        <string id="msg_0x2107" value="Power Users are included for backwards compatibility and possess limited administrative powers" />
        <string id="msg_0x2108" value="Users are prevented from making accidental or intentional system-wide changes and can run most applications" />
        <string id="msg_0x2109" value="Guests have the same access as members of the Users group by default, except for the Guest account which is further restricted" />
        <string id="msg_0x210A" value="Members can administer domain user and group accounts" />
        <string id="msg_0x210B" value="Members can administer printers installed on domain controllers" />
        <string id="msg_0x210C" value="Backup Operators can override security restrictions for the sole purpose of backing up or restoring files" />
        <string id="msg_0x210D" value="Supports file replication in a domain" />
        <string id="msg_0x210E" value="All domain guests" />
        <string id="msg_0x210F" value="Key Distribution Center Service Account" />
        <string id="msg_0x2110" value="All workstations and servers joined to the domain" />
        <string id="msg_0x2111" value="All domain controllers in the domain" />
        <string id="msg_0x2112" value="Designated administrators of the schema" />
        <string id="msg_0x2113" value="Members of this group are permitted to publish certificates to the directory" />
        <string id="msg_0x2114" value="Designated administrators of the enterprise" />
        <string id="msg_0x2115" value="Servers in this group can access remote access properties of users" />
        <string id="msg_0x2116" value="Members in this group can modify group policy for the domain" />
        <string id="msg_0x2117" value="A backward compatibility group which allows read access on all users and groups in the domain" />
        <string id="msg_0x2118" value="Members in this group are granted the right to logon remotely" />
        <string id="msg_0x2119" value="Administrators have complete and unrestricted access to the computer" />
        <string id="msg_0x211A" value="Members in this group can have some administrative privileges to manage configuration of networking features" />
        <string id="msg_0x211B" value="Members of this group can create incoming, one-way trusts to this forest" />
        <string id="msg_0x211C" value="Members of this group can access performance counter data locally and remotely" />
        <string id="msg_0x211D" value="Members of this group may schedule logging of performance counters, enable trace providers, and collect event traces both locally and via remote access to this computer" />
        <string id="msg_0x211E" value="Members of this group have access to the computed tokenGroupsGlobalAndUniversal attribute on User objects" />
        <string id="msg_0x211F" value="Members of this group can update user accounts in Active Directory with information about license issuance, for the purpose of tracking and reporting TS Per User CAL usage" />
        <string id="msg_0x2120" value="Members in this group are granted the right to install software" />
        <string id="msg_0x2121" value="Members are allowed to launch, activate and use Distributed COM objects on this machine." />
        <string id="msg_0x2122" value="Built-in group used by Internet Information Services." />
        <string id="msg_0x2125" value="Members are authorized to perform cryptographic operations." />
        <string id="msg_0x2127" value="Members in this group can have their passwords replicated to all read-only domain controllers in the domain" />
        <string id="msg_0x2128" value="Members in this group cannot have their passwords replicated to any read-only domain controllers in the domain" />
        <string id="msg_0x2129" value="Members of this group are Read-Only Domain Controllers in the domain" />
        <string id="msg_0x212A" value="Members of this group can read event logs from local machine" />
        <string id="msg_0x212B" value="Members of this group are Read-Only Domain Controllers in the enterprise" />
        <string id="msg_0x212C" value="Members of this group are allowed to connect to Certification Authorities in the enterprise" />
        <string id="msg_0x212D" value="Servers in this group enable users of RemoteApp programs and personal virtual desktops access to these resources. In Internet-facing deployments, these servers are typically deployed in an edge network. This group needs to be populated on servers running RD Connection Broker. RD Gateway servers and RD Web Access servers used in the deployment need to be in this group." />
        <string id="msg_0x212F" value="Servers in this group run virtual machines and host sessions where users RemoteApp programs and personal virtual desktops run. This group needs to be populated on servers running RD Connection Broker. RD Session Host servers and RD Virtualization Host servers used in the deployment need to be in this group." />
        <string id="msg_0x2130" value="Servers in this group can perform routine administrative actions on servers running Remote Desktop Services. This group needs to be populated on all servers in a Remote Desktop Services deployment. The servers running the RDS Central Management service must be included in this group." />
        <string id="msg_0x2131" value="Members of this group have complete and unrestricted access to all features of Hyper-V." />
        <string id="msg_0x2132" value="Members of this group that are domain controllers may be cloned." />
        <string id="msg_0x2133" value="Members of this group can remotely query authorization attributes and permissions for resources on this computer." />
        <string id="msg_0x2134" value="Members of this group can access WMI resources over management protocols (such as WS-Management via the Windows Remote Management service). This applies only to WMI namespaces that grant access to the user." />
        <string id="msg_0x2135" value="Protected Users" />
        <string id="msg_0x2136" value="Members of this group are afforded additional protections against authentication security threats. See http://go.microsoft.com/fwlink/?LinkId=298939 for more information." />
        <string id="msg_0x2137" value="A user account managed by the system." />
        <string id="msg_0x2138" value="Members of this group are managed by the system." />
        <string id="msg_0x2139" value="Storage Replica Administrators" />
        <string id="msg_0x213A" value="Members of this group have complete and unrestricted access to all features of Storage Replica." />
        <string id="msg_0x213B" value="Key Admins" />
        <string id="msg_0x213C" value="Members of this group can perform administrative actions on key objects within the domain." />
        <string id="msg_0x213D" value="Enterprise Key Admins" />
        <string id="msg_0x213E" value="Members of this group can perform administrative actions on key objects within the forest." />
        <string id="msg_0x400C" value="The account krbtgt was renamed to %1 to allow the Kerberos security package to install." />
        <string id="msg_0x4200" value="Security Enabled Local Group Changed to Security Enabled Universal Group." />
        <string id="msg_0x4201" value="Security Enabled Local Group Changed to Security Disabled Local Group." />
        <string id="msg_0x4202" value="Security Enabled Local Group Changed to Security Disabled Universal Group." />
        <string id="msg_0x4203" value="Security Enabled Global Group Changed to Security Enabled Universal Group." />
        <string id="msg_0x4204" value="Security Enabled Global Group Changed to Security Disabled Global Group." />
        <string id="msg_0x4205" value="Security Enabled Global Group Changed to Security Disabled Universal Group." />
        <string id="msg_0x4206" value="Security Enabled Universal Group Changed to Security Enabled Local Group." />
        <string id="msg_0x4207" value="Security Enabled Universal Group Changed to Security Enabled Global Group." />
        <string id="msg_0x4208" value="Security Enabled Universal Group Changed to Security Disabled Local Group." />
        <string id="msg_0x4209" value="Security Enabled Universal Group Changed to Security Disabled Global Group." />
        <string id="msg_0x420A" value="Security Enabled Universal Group Changed to Security Disabled Universal Group." />
        <string id="msg_0x420B" value="Security Disabled Local Group Changed to Security Enabled Local Group." />
        <string id="msg_0x420C" value="Security Disabled Local Group Changed to Security Enabled Universal Group." />
        <string id="msg_0x420D" value="Security Disabled Local Group Changed to Security Disabled Universal Group." />
        <string id="msg_0x420E" value="Security Disabled Global Group Changed to Security Enabled Global Group." />
        <string id="msg_0x420F" value="Security Disabled Global Group Changed to Security Enabled Universal Group." />
        <string id="msg_0x4210" value="Security Disabled Global Group Changed to Security Disabled Universal Group." />
        <string id="msg_0x4211" value="Security Disabled Universal Group Changed to Security Enabled Universal Group." />
        <string id="msg_0x4212" value="Security Disabled Universal Group Changed to Security Enabled Global Group." />
        <string id="msg_0x4213" value="Security Disabled Universal Group Changed to Security Enabled Universal Group." />
        <string id="msg_0x4214" value="Security Disabled Universal Group Changed to Security Disabled Local Group." />
        <string id="msg_0x4215" value="Security Disabled Universal Group Changed to Security Disabled Global Group." />
        <string id="msg_0x4216" value="Member Account Name Is Not Available." />
        <string id="msg_0x4217" value="Account Enabled." />
        <string id="msg_0x4218" value="Account Disabled." />
        <string id="msg_0x4219" value="Certain Bit(s) in User Account Control Field Has Been Changed." />
        <string id="msg_0x421B" value="Account Name Changed." />
        <string id="msg_0x421C" value="Password Policy" />
        <string id="msg_0x421D" value="Logoff Policy" />
        <string id="msg_0x421E" value="Oem Information" />
        <string id="msg_0x421F" value="Replication Information" />
        <string id="msg_0x4220" value="Domain Server Role" />
        <string id="msg_0x4221" value="Domain Server State" />
        <string id="msg_0x4222" value="Lockout Policy" />
        <string id="msg_0x4223" value="Modified Count" />
        <string id="msg_0x4224" value="Domain Mode" />
        <string id="msg_0x4225" value="Basic Application Group Changed to Ldap Query Application Group." />
        <string id="msg_0x4226" value="Ldap Query Application Group Changed to Basic Application Group." />
      </stringTable>
    </resources>
  </localization>
  <instrumentation>
    <events xmlns="http://schemas.microsoft.com/win/2004/08/events">
      <provider guid="{0D4FDC09-8C27-494A-BDA0-505E4FD8ADAE}" message="$(string.eventProviderName)" messageFileName="%SystemRoot%\System32\samsrv.dll" name="Microsoft-Windows-Directory-Services-SAM" resourceFileName="%SystemRoot%\System32\samsrv.dll" symbol="S_SAM_PROVIDER">
        <channels>
          <importChannel chid="System" name="System" />
        </channels>
        <templates>
          <template name="SAMMSG_COMMIT_FAILED" tid="T_0x3000">
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_REFRESH_FAILED" tid="T_0x3001">
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_RPC_INIT_FAILED" tid="T_0x3003">
            <binary name="LogStatus" />
          </template>
          <template name="SAMMSG_DUPLICATE_SID" tid="T_0x3005">
            <data inType="win:UnicodeString" name="AccountDistinguishedName" />
          </template>
          <template name="SAMMSG_LOCKOUT_NOT_UPDATED" tid="T_0x3006">
            <data inType="win:UnicodeString" name="UserName" />
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_DATABASE_FILE_NOT_DELETED" tid="T_0x3007">
            <data inType="win:UnicodeString" name="FilePath" />
            <binary name="WinError" />
          </template>
          <template name="SAMMSG_DATABASE_DIR_NOT_DELETED" tid="T_0x3008">
            <data inType="win:UnicodeString" name="DirectoryPath" />
            <binary name="WinError" />
          </template>
          <template name="SAMMSG_PROMOTED_TO_PDC" tid="T_0x3009">
            <data inType="win:UnicodeString" name="ComputerName" />
          </template>
          <template name="SAMMSG_DC_NEEDS_TO_BE_COMPUTER" tid="T_0x300A">
            <data inType="win:UnicodeString" name="ComputerName" />
          </template>
          <template name="SAMMSG_SITE_INFO_UPDATE_FAILED" tid="T_0x300B">
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_SITE_INFO_UPDATE_SUCCEEDED_ON" tid="T_0x300C" />
          <template name="SAMMSG_SITE_INFO_UPDATE_SUCCEEDED_OFF" tid="T_0x300D" />
          <template name="SAMMSG_CREDENTIAL_UPDATE_PKG_FAILED" tid="T_0x300E">
            <data inType="win:UnicodeString" name="SecurityPackage" />
            <data inType="win:UnicodeString" name="UserName" />
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_DUPLICATE_SID_WELLKNOWN_ACCOUNT" tid="T_0x300F">
            <data inType="win:UnicodeString" name="AccountDistinguishedName" />
          </template>
          <template name="SAMMSG_RENAME_DUPLICATE_ACCOUNT_NAME" tid="T_0x3010">
            <data inType="win:UnicodeString" name="AccountDistinguishedName" />
            <data inType="win:UnicodeString" name="SystemAssignedAccountName" />
          </template>
          <template name="SAMMSG_PDC_TASK_FAILURE" tid="T_0x3011">
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_DUPLICATE_ACCOUNT" tid="T_0x4000">
            <data inType="win:UnicodeString" name="AccountName" />
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_USER_NOT_UPGRADED" tid="T_0x4001">
            <data inType="win:UnicodeString" name="UserName" />
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_UNKNOWN_USER_NOT_UPGRADED" tid="T_0x4002">
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_ALIAS_NOT_UPGRADED" tid="T_0x4003">
            <data inType="win:UnicodeString" name="GroupName" />
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_UNKNOWN_ALIAS_NOT_UPGRADED" tid="T_0x4004">
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_GROUP_NOT_UPGRADED" tid="T_0x4005">
            <data inType="win:UnicodeString" name="GroupName" />
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_UNKNOWN_GROUP_NOT_UPGRADED" tid="T_0x4006">
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_ERROR_ALIAS_MEMBER" tid="T_0x4007">
            <data inType="win:UnicodeString" name="AccountDistinguishedName" />
            <data inType="win:UnicodeString" name="GroupName" />
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_ERROR_ALIAS_MEMBER_UNKNOWN" tid="T_0x4008">
            <data inType="win:UnicodeString" name="AccountSID" />
            <data inType="win:UnicodeString" name="AccountDistinguishedName" />
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_ERROR_GROUP_MEMBER" tid="T_0x4009">
            <data inType="win:UnicodeString" name="AccountDistinguishedName" />
            <data inType="win:UnicodeString" name="GroupName" />
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_ERROR_GROUP_MEMBER_UNKNOWN" tid="T_0x400A">
            <data inType="win:UInt32" name="AccountRID" />
            <data inType="win:UnicodeString" name="GroupName" />
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_FATAL_UPGRADE_ERROR" tid="T_0x400B">
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_ERROR_UPGRADE_USERPARMS" tid="T_0x400E">
            <data inType="win:UnicodeString" name="SecurityPackage" />
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_ERROR_SET_USERPARMS" tid="T_0x400F">
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_ACCEPTABLE_ERROR_UPGRADE_USER" tid="T_0x4010">
            <data inType="win:UnicodeString" name="UserName" />
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_MEMBERSHIP_SETUP_ERROR_NO_GROUP" tid="T_0x4011">
            <data inType="win:UnicodeString" name="AccountName" />
            <data inType="win:UnicodeString" name="GroupName" />
            <data inType="win:UnicodeString" name="ErrorMessage" />
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_MEMBERSHIP_SETUP_ERROR" tid="T_0x4012">
            <data inType="win:UnicodeString" name="AccountName" />
            <data inType="win:UnicodeString" name="GroupName" />
            <data inType="win:UnicodeString" name="ErrorMessage" />
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_USER_SETUP_ERROR" tid="T_0x4013">
            <data inType="win:UnicodeString" name="AccountName" />
            <data inType="win:UnicodeString" name="ErrorMessage" />
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_MACHINE_ACCOUNT_MISSING" tid="T_0x4015">
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_WELL_KNOWN_ACCOUNT_RECREATED" tid="T_0x4016">
            <data inType="win:UnicodeString" name="UserName" />
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_WELL_KNOWN_GROUP_RECREATED" tid="T_0x4017">
            <data inType="win:UnicodeString" name="GroupName" />
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_CHANGE_TO_NATIVE_MODE" tid="T_0x4018" />
          <template name="SAMMSG_FAILED_TO_ADD_SECURITY_PRINCIPAL" tid="T_0x4019">
            <data inType="win:UnicodeString" name="AccountName" />
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_FAILED_TO_ADD_ALL_SECURITY_PRINCIPALS" tid="T_0x401A">
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_FAILED_TO_RENAME_SECURITY_PRINCIPAL" tid="T_0x401B">
            <data inType="win:UnicodeString" name="AccountName" />
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_FAILED_TO_RENAME_ALL_SECURITY_PRINCIPALS" tid="T_0x401C">
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_MEMBERSHIP_REMOVAL_SETUP_ERROR" tid="T_0x401D">
            <data inType="win:UnicodeString" name="AccountName" />
            <data inType="win:UnicodeString" name="GroupName" />
            <data inType="win:UnicodeString" name="ErrorString" />
            <binary name="BinaryData" />
          </template>
          <template name="SAMMSG_GET_NEXT_RID_ERROR" tid="T_0x4102">
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_NO_RIDS_ASSIGNED" tid="T_0x4103">
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_MAX_DOMAIN_RID" tid="T_0x4104">
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_MAX_DC_RID" tid="T_0x4105">
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_INVALID_RID" tid="T_0x4106">
            <data inType="win:UInt32" name="ComputedRIDValue" />
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_REQUESTING_NEW_RID_POOL" tid="T_0x4107" />
          <template name="SAMMSG_RID_REQUEST_STATUS_SUCCESS" tid="T_0x4108">
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_RID_MANAGER_CREATION" tid="T_0x4109">
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_RID_REQUEST_STATUS_FAILURE" tid="T_0x410B">
            <data inType="win:UnicodeString" name="ErrorMessage" />
          </template>
          <template name="SAMMSG_BOOT_TO_RESTORE_MODE" tid="T_0x410C" />
          <template name="SAMMSG_INVALID_RID_BLOCK_SIZE" tid="T_0x410D">
            <data inType="win:UInt32" name="Maximum" />
          </template>
          <template name="SAMMSG_RID_POOL_INVALIDATED" tid="T_0x410E" />
          <template name="SAMMSG_INCREASING_GLOBAL_RID_MAXIMUM" tid="T_0x410F">
            <data inType="win:UInt32" name="NewValue" />
          </template>
          <template name="SAMMSG_RID_ARTIFICIAL_CEILING_WARNING" tid="T_0x4110">
            <data inType="win:UInt32" name="CeilingTriggerRid" />
          </template>
          <template name="SAMMSG_RID_ARTIFICIAL_CEILING_ACTIVATED" tid="T_0x4111">
            <data inType="win:UInt32" name="CeilingTriggerRid" />
          </template>
          <template name="SAMMSG_RID_CONSUMPTION_WARNING" tid="T_0x4112">
            <data inType="win:UInt32" name="RemainingRids" />
          </template>
          <template name="SAMMSG_FAILED_MACHINE_ACCOUNT_SECURE" tid="T_0x4227">
            <data inType="win:UnicodeString" name="ComputerName" />
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_FAILED_MACHINE_ACCOUNT_SECURE_RETRY" tid="T_0x4228">
            <data inType="win:UnicodeString" name="ComputerName" />
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_MACHINE_ACCOUNT_SECURE" tid="T_0x4229">
            <data inType="win:UnicodeString" name="ComputerName" />
            <binary name="ErrorCode" />
          </template>
          <template name="SAMMSG_OID_NOT_FOUND" tid="T_0x4230">
            <data inType="win:UnicodeString" name="OID" />
            <data inType="win:UInt32" name="ErrorCode" />
          </template>
          <template name="SAMMSG_NO_OID_TO_GROUP_LINK_ATTRIBUTE" tid="T_0x4231">
            <data inType="win:UnicodeString" name="OID" />
            <data inType="win:UnicodeString" name="OID Object DN" />
            <data inType="win:UInt32" name="ErrorCode" />
          </template>
          <template name="SAMMSG_DUPLICATE_OID_OBJECT" tid="T_0x4232">
            <data inType="win:UnicodeString" name="OID" />
          </template>
          <template name="SAMMSG_INVALID_OID_TO_GROUP_LINK" tid="T_0x4233">
            <data inType="win:UnicodeString" name="OID" />
            <data inType="win:UnicodeString" name="OID Object DN" />
            <data inType="win:UnicodeString" name="Group DN" />
            <data inType="win:UnicodeString" name="Group GUID" />
            <data inType="win:UnicodeString" name="Group SID" />
            <data inType="win:UInt32" name="ErrorCode" />
          </template>
          <template name="SAMMSG_MAPPED_GROUP_MODIFICATION_FAILED" tid="T_0x4234">
            <data inType="win:UnicodeString" name="Group DN" />
            <data inType="win:UnicodeString" name="Group GUID" />
            <data inType="win:UnicodeString" name="Group SID" />
            <data inType="win:UnicodeString" name="Operation" />
            <data inType="win:UInt32" name="ErrorCode" />
          </template>
          <template name="SAMMSG_CANNOT_LINK_OID_TO_GROUP" tid="T_0x4235">
            <data inType="win:UnicodeString" name="OID Name" />
            <data inType="win:UnicodeString" name="Group Name" />
            <data inType="win:UnicodeString" name="Group GUID" />
            <data inType="win:UnicodeString" name="Group SID" />
            <data inType="win:UInt32" name="ErrorCode" />
          </template>
          <template name="SAMMSG_INVALID_CLAIMS_DROPPED" tid="T_0x4236">
            <data inType="win:UnicodeString" name="User" />
            <data inType="win:UnicodeString" name="DroppedClaims" />
          </template>
          <template name="SAMMSG_CLAIMS_BLOB_DECODE_FAILED" tid="T_0x4237">
            <data inType="win:UnicodeString" name="User" />
            <data inType="win:UInt32" name="Error code:" />
          </template>
          <template name="SAMMSG_CLAIMS_BLOB_ENCODE_FAILED" tid="T_0x4238">
            <data inType="win:UnicodeString" name="User" />
            <data inType="win:UInt32" name="Error code:" />
          </template>
          <template name="SAMMSG_NOTIFICATION_PACKAGE_REGISTRATION_FAILED" tid="T_0x4239">
            <data inType="win:UnicodeString" name="NotificationPackage:" />
            <data inType="win:UnicodeString" name="Registry key:" />
            <data inType="win:UnicodeString" name="Registry value:" />
            <data inType="win:UInt32" name="Error code:" />
          </template>
          <template name="SAMMSG_NOTIFICATION_TCP_DISABLED" tid="T_0x4240" />
          <template name="SAMMSG_NOTIFICATION_PASSWORD_LEGACY_MODE_ENABLED" tid="T_0x4241" />
        </templates>
        <events>
          <event channel="System" level="win:Error" message="$(string.event_0x3000)" symbol="SAMMSG_COMMIT_FAILED" template="T_0x3000" value="0x3000" />
          <event channel="System" level="win:Error" message="$(string.event_0x3001)" symbol="SAMMSG_REFRESH_FAILED" template="T_0x3001" value="0x3001" />
          <event channel="System" level="win:Error" message="$(string.event_0x3003)" symbol="SAMMSG_RPC_INIT_FAILED" template="T_0x3003" value="0x3003" />
          <event channel="System" level="win:Error" message="$(string.event_0x3005)" symbol="SAMMSG_DUPLICATE_SID" template="T_0x3005" value="0x3005" />
          <event channel="System" level="win:Error" message="$(string.event_0x3006)" symbol="SAMMSG_LOCKOUT_NOT_UPDATED" template="T_0x3006" value="0x3006" />
          <event channel="System" level="win:Informational" message="$(string.event_0x3007)" symbol="SAMMSG_DATABASE_FILE_NOT_DELETED" template="T_0x3007" value="0x3007" />
          <event channel="System" level="win:Informational" message="$(string.event_0x3008)" symbol="SAMMSG_DATABASE_DIR_NOT_DELETED" template="T_0x3008" value="0x3008" />
          <event channel="System" level="win:Informational" message="$(string.event_0x3009)" symbol="SAMMSG_PROMOTED_TO_PDC" template="T_0x3009" value="0x3009" />
          <event channel="System" level="win:Error" message="$(string.event_0x300A)" symbol="SAMMSG_DC_NEEDS_TO_BE_COMPUTER" template="T_0x300A" value="0x300A" />
          <event channel="System" level="win:Warning" message="$(string.event_0x300B)" symbol="SAMMSG_SITE_INFO_UPDATE_FAILED" template="T_0x300B" value="0x300B" />
          <event channel="System" level="win:Informational" message="$(string.event_0x300C)" symbol="SAMMSG_SITE_INFO_UPDATE_SUCCEEDED_ON" template="T_0x300C" value="0x300C" />
          <event channel="System" level="win:Informational" message="$(string.event_0x300D)" symbol="SAMMSG_SITE_INFO_UPDATE_SUCCEEDED_OFF" template="T_0x300D" value="0x300D" />
          <event channel="System" level="win:Error" message="$(string.event_0x300E)" symbol="SAMMSG_CREDENTIAL_UPDATE_PKG_FAILED" template="T_0x300E" value="0x300E" />
          <event channel="System" level="win:Error" message="$(string.event_0x300F)" symbol="SAMMSG_DUPLICATE_SID_WELLKNOWN_ACCOUNT" template="T_0x300F" value="0x300F" />
          <event channel="System" level="win:Informational" message="$(string.event_0x3010)" symbol="SAMMSG_RENAME_DUPLICATE_ACCOUNT_NAME" template="T_0x3010" value="0x3010" />
          <event channel="System" level="win:Warning" message="$(string.event_0x3011)" symbol="SAMMSG_PDC_TASK_FAILURE" template="T_0x3011" value="0x3011" />
          <event channel="System" level="win:Informational" message="$(string.event_0x4000)" symbol="SAMMSG_DUPLICATE_ACCOUNT" template="T_0x4000" value="0x4000" />
          <event channel="System" level="win:Warning" message="$(string.event_0x4001)" symbol="SAMMSG_USER_NOT_UPGRADED" template="T_0x4001" value="0x4001" />
          <event channel="System" level="win:Warning" message="$(string.event_0x4002)" symbol="SAMMSG_UNKNOWN_USER_NOT_UPGRADED" template="T_0x4002" value="0x4002" />
          <event channel="System" level="win:Warning" message="$(string.event_0x4003)" symbol="SAMMSG_ALIAS_NOT_UPGRADED" template="T_0x4003" value="0x4003" />
          <event channel="System" level="win:Warning" message="$(string.event_0x4004)" symbol="SAMMSG_UNKNOWN_ALIAS_NOT_UPGRADED" template="T_0x4004" value="0x4004" />
          <event channel="System" level="win:Warning" message="$(string.event_0x4005)" symbol="SAMMSG_GROUP_NOT_UPGRADED" template="T_0x4005" value="0x4005" />
          <event channel="System" level="win:Warning" message="$(string.event_0x4006)" symbol="SAMMSG_UNKNOWN_GROUP_NOT_UPGRADED" template="T_0x4006" value="0x4006" />
          <event channel="System" level="win:Warning" message="$(string.event_0x4007)" symbol="SAMMSG_ERROR_ALIAS_MEMBER" template="T_0x4007" value="0x4007" />
          <event channel="System" level="win:Warning" message="$(string.event_0x4008)" symbol="SAMMSG_ERROR_ALIAS_MEMBER_UNKNOWN" template="T_0x4008" value="0x4008" />
          <event channel="System" level="win:Warning" message="$(string.event_0x4009)" symbol="SAMMSG_ERROR_GROUP_MEMBER" template="T_0x4009" value="0x4009" />
          <event channel="System" level="win:Warning" message="$(string.event_0x400A)" symbol="SAMMSG_ERROR_GROUP_MEMBER_UNKNOWN" template="T_0x400A" value="0x400A" />
          <event channel="System" level="win:Error" message="$(string.event_0x400B)" symbol="SAMMSG_FATAL_UPGRADE_ERROR" template="T_0x400B" value="0x400B" />
          <event channel="System" level="win:Error" message="$(string.event_0x400E)" symbol="SAMMSG_ERROR_UPGRADE_USERPARMS" template="T_0x400E" value="0x400E" />
          <event channel="System" level="win:Error" message="$(string.event_0x400F)" symbol="SAMMSG_ERROR_SET_USERPARMS" template="T_0x400F" value="0x400F" />
          <event channel="System" level="win:Informational" message="$(string.event_0x4010)" symbol="SAMMSG_ACCEPTABLE_ERROR_UPGRADE_USER" template="T_0x4010" value="0x4010" />
          <event channel="System" level="win:Informational" message="$(string.event_0x4011)" symbol="SAMMSG_MEMBERSHIP_SETUP_ERROR_NO_GROUP" template="T_0x4011" value="0x4011" />
          <event channel="System" level="win:Informational" message="$(string.event_0x4012)" symbol="SAMMSG_MEMBERSHIP_SETUP_ERROR" template="T_0x4012" value="0x4012" />
          <event channel="System" level="win:Informational" message="$(string.event_0x4013)" symbol="SAMMSG_USER_SETUP_ERROR" template="T_0x4013" value="0x4013" />
          <event channel="System" level="win:Error" message="$(string.event_0x4015)" symbol="SAMMSG_MACHINE_ACCOUNT_MISSING" template="T_0x4015" value="0x4015" />
          <event channel="System" level="win:Warning" message="$(string.event_0x4016)" symbol="SAMMSG_WELL_KNOWN_ACCOUNT_RECREATED" template="T_0x4016" value="0x4016" />
          <event channel="System" level="win:Warning" message="$(string.event_0x4017)" symbol="SAMMSG_WELL_KNOWN_GROUP_RECREATED" template="T_0x4017" value="0x4017" />
          <event channel="System" level="win:Informational" message="$(string.event_0x4018)" symbol="SAMMSG_CHANGE_TO_NATIVE_MODE" template="T_0x4018" value="0x4018" />
          <event channel="System" level="win:Error" message="$(string.event_0x4019)" symbol="SAMMSG_FAILED_TO_ADD_SECURITY_PRINCIPAL" template="T_0x4019" value="0x4019" />
          <event channel="System" level="win:Error" message="$(string.event_0x401A)" symbol="SAMMSG_FAILED_TO_ADD_ALL_SECURITY_PRINCIPALS" template="T_0x401A" value="0x401A" />
          <event channel="System" level="win:Error" message="$(string.event_0x401B)" symbol="SAMMSG_FAILED_TO_RENAME_SECURITY_PRINCIPAL" template="T_0x401B" value="0x401B" />
          <event channel="System" level="win:Error" message="$(string.event_0x401C)" symbol="SAMMSG_FAILED_TO_RENAME_ALL_SECURITY_PRINCIPALS" template="T_0x401C" value="0x401C" />
          <event channel="System" level="win:Informational" message="$(string.event_0x401D)" symbol="SAMMSG_MEMBERSHIP_REMOVAL_SETUP_ERROR" template="T_0x401D" value="0x401D" />
          <event channel="System" level="win:Error" message="$(string.event_0x4102)" symbol="SAMMSG_GET_NEXT_RID_ERROR" template="T_0x4102" value="0x4102" />
          <event channel="System" level="win:Error" message="$(string.event_0x4103)" symbol="SAMMSG_NO_RIDS_ASSIGNED" template="T_0x4103" value="0x4103" />
          <event channel="System" level="win:Error" message="$(string.event_0x4104)" symbol="SAMMSG_MAX_DOMAIN_RID" template="T_0x4104" value="0x4104" />
          <event channel="System" level="win:Error" message="$(string.event_0x4105)" symbol="SAMMSG_MAX_DC_RID" template="T_0x4105" value="0x4105" />
          <event channel="System" level="win:Error" message="$(string.event_0x4106)" symbol="SAMMSG_INVALID_RID" template="T_0x4106" value="0x4106" />
          <event channel="System" level="win:Informational" message="$(string.event_0x4107)" symbol="SAMMSG_REQUESTING_NEW_RID_POOL" template="T_0x4107" value="0x4107" />
          <event channel="System" level="win:Informational" message="$(string.event_0x4108)" symbol="SAMMSG_RID_REQUEST_STATUS_SUCCESS" template="T_0x4108" value="0x4108" />
          <event channel="System" level="win:Error" message="$(string.event_0x4109)" symbol="SAMMSG_RID_MANAGER_CREATION" template="T_0x4109" value="0x4109" />
          <event channel="System" level="win:Error" message="$(string.event_0x410B)" symbol="SAMMSG_RID_REQUEST_STATUS_FAILURE" template="T_0x410B" value="0x410B" />
          <event channel="System" level="win:Informational" message="$(string.event_0x410C)" symbol="SAMMSG_BOOT_TO_RESTORE_MODE" template="T_0x410C" value="0x410C" />
          <event channel="System" level="win:Warning" message="$(string.event_0x410D)" symbol="SAMMSG_INVALID_RID_BLOCK_SIZE" template="T_0x410D" value="0x410D" />
          <event channel="System" level="win:Informational" message="$(string.event_0x410E)" symbol="SAMMSG_RID_POOL_INVALIDATED" template="T_0x410E" value="0x410E" />
          <event channel="System" level="win:Informational" message="$(string.event_0x410F)" symbol="SAMMSG_INCREASING_GLOBAL_RID_MAXIMUM" template="T_0x410F" value="0x410F" />
          <event channel="System" level="win:Warning" message="$(string.event_0x4110)" symbol="SAMMSG_RID_ARTIFICIAL_CEILING_WARNING" template="T_0x4110" value="0x4110" />
          <event channel="System" level="win:Error" message="$(string.event_0x4111)" symbol="SAMMSG_RID_ARTIFICIAL_CEILING_ACTIVATED" template="T_0x4111" value="0x4111" />
          <event channel="System" level="win:Warning" message="$(string.event_0x4112)" symbol="SAMMSG_RID_CONSUMPTION_WARNING" template="T_0x4112" value="0x4112" />
          <event channel="System" level="win:Error" message="$(string.event_0x4227)" symbol="SAMMSG_FAILED_MACHINE_ACCOUNT_SECURE" template="T_0x4227" value="0x4227" />
          <event channel="System" level="win:Error" message="$(string.event_0x4228)" symbol="SAMMSG_FAILED_MACHINE_ACCOUNT_SECURE_RETRY" template="T_0x4228" value="0x4228" />
          <event channel="System" level="win:Informational" message="$(string.event_0x4229)" symbol="SAMMSG_MACHINE_ACCOUNT_SECURE" template="T_0x4229" value="0x4229" />
          <event channel="System" level="win:Informational" message="$(string.event_0x4230)" symbol="SAMMSG_OID_NOT_FOUND" template="T_0x4230" value="0x4230" />
          <event channel="System" level="win:Informational" message="$(string.event_0x4231)" symbol="SAMMSG_NO_OID_TO_GROUP_LINK_ATTRIBUTE" template="T_0x4231" value="0x4231" />
          <event channel="System" level="win:Informational" message="$(string.event_0x4232)" symbol="SAMMSG_DUPLICATE_OID_OBJECT" template="T_0x4232" value="0x4232" />
          <event channel="System" level="win:Error" message="$(string.event_0x4233)" symbol="SAMMSG_INVALID_OID_TO_GROUP_LINK" template="T_0x4233" value="0x4233" />
          <event channel="System" level="win:Error" message="$(string.event_0x4234)" symbol="SAMMSG_MAPPED_GROUP_MODIFICATION_FAILED" template="T_0x4234" value="0x4234" />
          <event channel="System" level="win:Error" message="$(string.event_0x4235)" symbol="SAMMSG_CANNOT_LINK_OID_TO_GROUP" template="T_0x4235" value="0x4235" />
          <event channel="System" level="win:Warning" message="$(string.event_0x4236)" symbol="SAMMSG_INVALID_CLAIMS_DROPPED" template="T_0x4236" value="0x4236" />
          <event channel="System" level="win:Warning" message="$(string.event_0x4237)" symbol="SAMMSG_CLAIMS_BLOB_DECODE_FAILED" template="T_0x4237" value="0x4237" />
          <event channel="System" level="win:Error" message="$(string.event_0x4238)" symbol="SAMMSG_CLAIMS_BLOB_ENCODE_FAILED" template="T_0x4238" value="0x4238" />
          <event channel="System" level="win:Error" message="$(string.event_0x4239)" symbol="SAMMSG_NOTIFICATION_PACKAGE_REGISTRATION_FAILED" template="T_0x4239" value="0x4239" />
          <event channel="System" level="win:Informational" message="$(string.event_0x4240)" symbol="SAMMSG_NOTIFICATION_TCP_DISABLED" template="T_0x4240" value="0x4240" />
          <event channel="System" level="win:Warning" message="$(string.event_0x4241)" symbol="SAMMSG_NOTIFICATION_PASSWORD_LEGACY_MODE_ENABLED" template="T_0x4241" value="0x4241" />
        </events>
      </provider>
      <messageTable>
        <message message="$(string.event_0x3000)" value="0x3000" />
        <message message="$(string.event_0x3001)" value="0x3001" />
        <message message="$(string.event_0x3003)" value="0x3003" />
        <message message="$(string.event_0x3005)" value="0x3005" />
        <message message="$(string.event_0x3006)" value="0x3006" />
        <message message="$(string.event_0x3007)" value="0x3007" />
        <message message="$(string.event_0x3008)" value="0x3008" />
        <message message="$(string.event_0x3009)" value="0x3009" />
        <message message="$(string.event_0x300A)" value="0x300A" />
        <message message="$(string.event_0x300B)" value="0x300B" />
        <message message="$(string.event_0x300C)" value="0x300C" />
        <message message="$(string.event_0x300D)" value="0x300D" />
        <message message="$(string.event_0x300E)" value="0x300E" />
        <message message="$(string.event_0x300F)" value="0x300F" />
        <message message="$(string.event_0x3010)" value="0x3010" />
        <message message="$(string.event_0x3011)" value="0x3011" />
        <message message="$(string.event_0x4000)" value="0x4000" />
        <message message="$(string.event_0x4001)" value="0x4001" />
        <message message="$(string.event_0x4002)" value="0x4002" />
        <message message="$(string.event_0x4003)" value="0x4003" />
        <message message="$(string.event_0x4004)" value="0x4004" />
        <message message="$(string.event_0x4005)" value="0x4005" />
        <message message="$(string.event_0x4006)" value="0x4006" />
        <message message="$(string.event_0x4007)" value="0x4007" />
        <message message="$(string.event_0x4008)" value="0x4008" />
        <message message="$(string.event_0x4009)" value="0x4009" />
        <message message="$(string.event_0x400A)" value="0x400A" />
        <message message="$(string.event_0x400B)" value="0x400B" />
        <message message="$(string.event_0x400E)" value="0x400E" />
        <message message="$(string.event_0x400F)" value="0x400F" />
        <message message="$(string.event_0x4010)" value="0x4010" />
        <message message="$(string.event_0x4011)" value="0x4011" />
        <message message="$(string.event_0x4012)" value="0x4012" />
        <message message="$(string.event_0x4013)" value="0x4013" />
        <message message="$(string.event_0x4015)" value="0x4015" />
        <message message="$(string.event_0x4016)" value="0x4016" />
        <message message="$(string.event_0x4017)" value="0x4017" />
        <message message="$(string.event_0x4018)" value="0x4018" />
        <message message="$(string.event_0x4019)" value="0x4019" />
        <message message="$(string.event_0x401A)" value="0x401A" />
        <message message="$(string.event_0x401B)" value="0x401B" />
        <message message="$(string.event_0x401C)" value="0x401C" />
        <message message="$(string.event_0x401D)" value="0x401D" />
        <message message="$(string.event_0x4102)" value="0x4102" />
        <message message="$(string.event_0x4103)" value="0x4103" />
        <message message="$(string.event_0x4104)" value="0x4104" />
        <message message="$(string.event_0x4105)" value="0x4105" />
        <message message="$(string.event_0x4106)" value="0x4106" />
        <message message="$(string.event_0x4107)" value="0x4107" />
        <message message="$(string.event_0x4108)" value="0x4108" />
        <message message="$(string.event_0x4109)" value="0x4109" />
        <message message="$(string.event_0x410B)" value="0x410B" />
        <message message="$(string.event_0x410C)" value="0x410C" />
        <message message="$(string.event_0x410D)" value="0x410D" />
        <message message="$(string.event_0x410E)" value="0x410E" />
        <message message="$(string.event_0x410F)" value="0x410F" />
        <message message="$(string.event_0x4110)" value="0x4110" />
        <message message="$(string.event_0x4111)" value="0x4111" />
        <message message="$(string.event_0x4112)" value="0x4112" />
        <message message="$(string.event_0x4227)" value="0x4227" />
        <message message="$(string.event_0x4228)" value="0x4228" />
        <message message="$(string.event_0x4229)" value="0x4229" />
        <message message="$(string.msg_0x2000)" symbol="SAMP_USER_NAME_ADMIN" value="0x00002000" />
        <message message="$(string.msg_0x2001)" symbol="SAMP_USER_NAME_GUEST" value="0x00002001" />
        <message message="$(string.msg_0x2002)" symbol="SAMP_GROUP_NAME_ADMINS" value="0x00002002" />
        <message message="$(string.msg_0x2003)" symbol="SAMP_GROUP_NAME_USERS" value="0x00002003" />
        <message message="$(string.msg_0x2004)" symbol="SAMP_GROUP_NAME_NONE" value="0x00002004" />
        <message message="$(string.msg_0x2005)" symbol="SAMP_ALIAS_NAME_ADMINS" value="0x00002005" />
        <message message="$(string.msg_0x2006)" symbol="SAMP_ALIAS_NAME_SERVER_OPS" value="0x00002006" />
        <message message="$(string.msg_0x2007)" symbol="SAMP_ALIAS_NAME_POWER_USERS" value="0x00002007" />
        <message message="$(string.msg_0x2008)" symbol="SAMP_ALIAS_NAME_USERS" value="0x00002008" />
        <message message="$(string.msg_0x2009)" symbol="SAMP_ALIAS_NAME_GUESTS" value="0x00002009" />
        <message message="$(string.msg_0x200A)" symbol="SAMP_ALIAS_NAME_ACCOUNT_OPS" value="0x0000200A" />
        <message message="$(string.msg_0x200B)" symbol="SAMP_ALIAS_NAME_PRINT_OPS" value="0x0000200B" />
        <message message="$(string.msg_0x200C)" symbol="SAMP_ALIAS_NAME_BACKUP_OPS" value="0x0000200C" />
        <message message="$(string.msg_0x200D)" symbol="SAMP_ALIAS_NAME_REPLICATOR" value="0x0000200D" />
        <message message="$(string.msg_0x200E)" symbol="SAMP_GROUP_NAME_GUESTS" value="0x0000200E" />
        <message message="$(string.msg_0x200F)" symbol="SAMP_NAME_CONFLICT_RDN" value="0x0000200F" />
        <message message="$(string.msg_0x2010)" symbol="SAMP_USER_NAME_KRBTGT" value="0x00002010" />
        <message message="$(string.msg_0x2011)" symbol="SAMP_GROUP_NAME_COMPUTERS" value="0x00002011" />
        <message message="$(string.msg_0x2012)" symbol="SAMP_GROUP_NAME_CONTROLLERS" value="0x00002012" />
        <message message="$(string.msg_0x2013)" symbol="SAMP_GROUP_NAME_SCHEMA_ADMINS" value="0x00002013" />
        <message message="$(string.msg_0x2014)" symbol="SAMP_GROUP_NAME_CERT_ADMINS" value="0x00002014" />
        <message message="$(string.msg_0x2015)" symbol="SAMP_GROUP_NAME_ENTERPRISE_ADMINS" value="0x00002015" />
        <message message="$(string.msg_0x2016)" symbol="SAMP_ALIAS_NAME_RAS_SERVERS" value="0x00002016" />
        <message message="$(string.msg_0x2017)" symbol="SAMP_GROUP_NAME_POLICY_ADMINS" value="0x00002017" />
        <message message="$(string.msg_0x2018)" symbol="SAMP_ALIAS_NAME_PREW2KCOMPACCESS" value="0x00002018" />
        <message message="$(string.msg_0x2019)" symbol="SAMP_WELL_KNOWN_ALIAS_EVERYONE" value="0x00002019" />
        <message message="$(string.msg_0x201A)" symbol="SAMP_ALIAS_NAME_REMOTE_DESKTOP_USERS" value="0x0000201A" />
        <message message="$(string.msg_0x201B)" symbol="SAMP_ALIAS_NAME_ADMINS_PERS" value="0x0000201B" />
        <message message="$(string.msg_0x201C)" symbol="SAMP_WELL_KNOWN_ALIAS_ANONYMOUS_LOGON" value="0x0000201C" />
        <message message="$(string.msg_0x201D)" symbol="SAMP_ALIAS_NAME_NETWORK_CONFIGURATION_OPS" value="0x0000201D" />
        <message message="$(string.msg_0x201E)" symbol="SAMP_ALIAS_NAME_INCOMING_FOREST_TRUST_BUILDERS" value="0x0000201E" />
        <message message="$(string.msg_0x201F)" symbol="SAMP_ALIAS_NAME_MONITORING_USERS" value="0x0000201F" />
        <message message="$(string.msg_0x2020)" symbol="SAMP_ALIAS_NAME_LOGGING_USERS" value="0x00002020" />
        <message message="$(string.msg_0x2021)" symbol="SAMP_ALIAS_NAME_AUTHORIZATIONACCESS" value="0x00002021" />
        <message message="$(string.msg_0x2022)" symbol="SAMP_WELL_KNOWN_ALIAS_NETWORK_SERVICE" value="0x00002022" />
        <message message="$(string.msg_0x2023)" symbol="SAMP_WELL_KNOWN_ALIAS_ENTERPRISE_DOMAIN_CONTROLLERS" value="0x00002023" />
        <message message="$(string.msg_0x2024)" symbol="SAMP_ALIAS_NAME_TS_LICENSE_SERVERS" value="0x00002024" />
        <message message="$(string.msg_0x2025)" symbol="SAMP_ALIAS_NAME_TRUSTED_INSTALLERS" value="0x00002025" />
        <message message="$(string.msg_0x2026)" symbol="SAMP_ALIAS_NAME_DCOM_USERS" value="0x00002026" />
        <message message="$(string.msg_0x2027)" symbol="SAMP_ALIAS_NAME_IUSERS" value="0x00002027" />
        <message message="$(string.msg_0x202A)" symbol="SAMP_ALIAS_NAME_CRYPTO_OPERATORS" value="0x0000202A" />
        <message message="$(string.msg_0x202B)" symbol="SAMP_WELL_KNOWN_IUSER_SID" value="0x0000202B" />
        <message message="$(string.msg_0x202D)" symbol="SAMP_ALIAS_NAME_CACHEABLE_PRINCIPALS_GROUP" value="0x0000202D" />
        <message message="$(string.msg_0x202E)" symbol="SAMP_ALIAS_NAME_NON_CACHEABLE_PRINCIPALS_GROUP" value="0x0000202E" />
        <message message="$(string.msg_0x202F)" symbol="SAMP_GROUP_NAME_READONLY_CONTROLLERS" value="0x0000202F" />
        <message message="$(string.msg_0x2030)" symbol="SAMP_GROUP_NAME_ENTERPRISE_READONLY_DOMAIN_CONTROLLERS" value="0x00002030" />
        <message message="$(string.msg_0x2031)" symbol="SAMP_ALIAS_NAME_EVENT_LOG_READERS_GROUP" value="0x00002031" />
        <message message="$(string.msg_0x2032)" symbol="SAMP_ALIAS_NAME_CERTSVC_DCOM_ACCESS_GROUP" value="0x00002032" />
        <message message="$(string.msg_0x2033)" symbol="SAMP_ALIAS_NAME_RDS_REMOTE_ACCESS_SERVERS" value="0x00002033" />
        <message message="$(string.msg_0x2034)" symbol="SAMP_ALIAS_NAME_RDS_ENDPOINT_SERVERS" value="0x00002034" />
        <message message="$(string.msg_0x2035)" symbol="SAMP_ALIAS_NAME_RDS_MANAGEMENT_SERVERS" value="0x00002035" />
        <message message="$(string.msg_0x2036)" symbol="SAMP_ALIAS_NAME_HYPER_V_ADMINS" value="0x00002036" />
        <message message="$(string.msg_0x2037)" symbol="SAMP_GROUP_NAME_CLONEABLE_CONTROLLERS" value="0x00002037" />
        <message message="$(string.msg_0x2038)" symbol="SAMP_ALIAS_NAME_ACCESS_CONTROL_ASSISTANCE_OPS" value="0x00002038" />
        <message message="$(string.msg_0x2039)" symbol="SAMP_ALIAS_NAME_REMOTE_MANAGEMENT_USERS" value="0x00002039" />
        <message message="$(string.msg_0x203A)" symbol="SAMP_USER_NAME_DSMA" value="0x0000203A" />
        <message message="$(string.msg_0x203B)" symbol="SAMP_ALIAS_NAME_DSMA" value="0x0000203B" />
        <message message="$(string.msg_0x2100)" symbol="SAMP_USER_COMMENT_ADMIN" value="0x00002100" />
        <message message="$(string.msg_0x2101)" symbol="SAMP_USER_COMMENT_GUEST" value="0x00002101" />
        <message message="$(string.msg_0x2102)" symbol="SAMP_GROUP_COMMENT_ADMINS" value="0x00002102" />
        <message message="$(string.msg_0x2103)" symbol="SAMP_GROUP_COMMENT_USERS" value="0x00002103" />
        <message message="$(string.msg_0x2104)" symbol="SAMP_GROUP_COMMENT_NONE" value="0x00002104" />
        <message message="$(string.msg_0x2105)" symbol="SAMP_ALIAS_COMMENT_ADMINS" value="0x00002105" />
        <message message="$(string.msg_0x2106)" symbol="SAMP_ALIAS_COMMENT_SERVER_OPS" value="0x00002106" />
        <message message="$(string.msg_0x2107)" symbol="SAMP_ALIAS_COMMENT_POWER_USERS" value="0x00002107" />
        <message message="$(string.msg_0x2108)" symbol="SAMP_ALIAS_COMMENT_USERS" value="0x00002108" />
        <message message="$(string.msg_0x2109)" symbol="SAMP_ALIAS_COMMENT_GUESTS" value="0x00002109" />
        <message message="$(string.msg_0x210A)" symbol="SAMP_ALIAS_COMMENT_ACCOUNT_OPS" value="0x0000210A" />
        <message message="$(string.msg_0x210B)" symbol="SAMP_ALIAS_COMMENT_PRINT_OPS" value="0x0000210B" />
        <message message="$(string.msg_0x210C)" symbol="SAMP_ALIAS_COMMENT_BACKUP_OPS" value="0x0000210C" />
        <message message="$(string.msg_0x210D)" symbol="SAMP_ALIAS_COMMENT_REPLICATOR" value="0x0000210D" />
        <message message="$(string.msg_0x210E)" symbol="SAMP_GROUP_COMMENT_GUESTS" value="0x0000210E" />
        <message message="$(string.msg_0x210F)" symbol="SAMP_USER_COMMENT_KRBTGT" value="0x0000210F" />
        <message message="$(string.msg_0x2110)" symbol="SAMP_GROUP_COMMENT_COMPUTERS" value="0x00002110" />
        <message message="$(string.msg_0x2111)" symbol="SAMP_GROUP_COMMENT_CONTROLLERS" value="0x00002111" />
        <message message="$(string.msg_0x2112)" symbol="SAMP_GROUP_COMMENT_SCHEMA_ADMINS" value="0x00002112" />
        <message message="$(string.msg_0x2113)" symbol="SAMP_GROUP_COMMENT_CERT_ADMINS" value="0x00002113" />
        <message message="$(string.msg_0x2114)" symbol="SAMP_GROUP_COMMENT_ENTERPRISE_ADMINS" value="0x00002114" />
        <message message="$(string.msg_0x2115)" symbol="SAMP_ALIAS_COMMENT_RAS_SERVERS" value="0x00002115" />
        <message message="$(string.msg_0x2116)" symbol="SAMP_GROUP_COMMENT_POLICY_ADMINS" value="0x00002116" />
        <message message="$(string.msg_0x2117)" symbol="SAMP_ALIAS_COMMENT_PREW2KCOMPACCESS" value="0x00002117" />
        <message message="$(string.msg_0x2118)" symbol="SAMP_ALIAS_COMMENT_REMOTE_DESKTOP_USERS" value="0x00002118" />
        <message message="$(string.msg_0x2120)" symbol="SAMP_ALIAS_COMMENT_TRUSTED_INSTALLERS" value="0x00002120" />
        <message message="$(string.msg_0x2121)" symbol="SAMP_ALIAS_COMMENT_DCOM_USERS" value="0x00002121" />
        <message message="$(string.msg_0x2122)" symbol="SAMP_ALIAS_COMMENT_IUSERS" value="0x00002122" />
        <message message="$(string.msg_0x2125)" symbol="SAMP_ALIAS_COMMENT_CRYPTO_OPERATORS" value="0x00002125" />
        <message message="$(string.msg_0x2129)" symbol="SAMP_GROUP_COMMENT_READONLY_CONTROLLERS" value="0x00002129" />
        <message message="$(string.msg_0x2119)" symbol="SAMP_ALIAS_COMMENT_ADMINS_PERS" value="0x00002119" />
        <message message="$(string.msg_0x211A)" symbol="SAMP_ALIAS_COMMENT_NETWORK_CONFIGURATION_OPS" value="0x0000211A" />
        <message message="$(string.msg_0x211B)" symbol="SAMP_ALIAS_COMMENT_INCOMING_FOREST_TRUST_BUILDERS" value="0x0000211B" />
        <message message="$(string.msg_0x211C)" symbol="SAMP_ALIAS_COMMENT_MONITORING_USERS" value="0x0000211C" />
        <message message="$(string.msg_0x211D)" symbol="SAMP_ALIAS_COMMENT_LOGGING_USERS" value="0x0000211D" />
        <message message="$(string.msg_0x211E)" symbol="SAMP_ALIAS_COMMENT_AUTHORIZATIONACCESS" value="0x0000211E" />
        <message message="$(string.msg_0x211F)" symbol="SAMP_ALIAS_COMMENT_TS_LICENSE_SERVERS" value="0x0000211F" />
        <message message="$(string.msg_0x2127)" symbol="SAMP_ALIAS_COMMENT_CACHEABLE_PRINCIPALS_GROUP" value="0x00002127" />
        <message message="$(string.msg_0x2128)" symbol="SAMP_ALIAS_COMMENT_NON_CACHEABLE_PRINCIPALS_GROUP" value="0x00002128" />
        <message message="$(string.msg_0x212A)" symbol="SAMP_ALIAS_COMMENT_EVENT_LOG_READERS_GROUP" value="0x0000212A" />
        <message message="$(string.msg_0x212B)" symbol="SAMP_GROUP_COMMENT_ENTERPRISE_READONLY_DOMAIN_CONTROLLERS" value="0x0000212B" />
        <message message="$(string.msg_0x212C)" symbol="SAMP_ALIAS_COMMENT_CERTSVC_DCOM_ACCESS_GROUP" value="0x0000212C" />
        <message message="$(string.msg_0x212D)" symbol="SAMP_ALIAS_COMMENT_RDS_REMOTE_ACCESS_SERVERS" value="0x0000212D" />
        <message message="$(string.msg_0x212F)" symbol="SAMP_ALIAS_COMMENT_RDS_ENDPOINT_SERVERS" value="0x0000212F" />
        <message message="$(string.msg_0x2130)" symbol="SAMP_ALIAS_COMMENT_RDS_MANAGEMENT_SERVERS" value="0x00002130" />
        <message message="$(string.msg_0x2131)" symbol="SAMP_ALIAS_COMMENT_HYPER_V_ADMINS" value="0x00002131" />
        <message message="$(string.msg_0x2132)" symbol="SAMP_GROUP_COMMENT_CLONEABLE_CONTROLLERS" value="0x00002132" />
        <message message="$(string.msg_0x2133)" symbol="SAMP_ALIAS_COMMENT_ACCESS_CONTROL_ASSISTANCE_OPS" value="0x00002133" />
        <message message="$(string.msg_0x2134)" symbol="SAMP_ALIAS_COMMENT_REMOTE_MANAGEMENT_USERS" value="0x00002134" />
        <message message="$(string.msg_0x2135)" symbol="SAMP_GROUP_NAME_PROTECTED_USERS" value="0x00002135" />
        <message message="$(string.msg_0x2136)" symbol="SAMP_GROUP_COMMENT_PROTECTED_USERS" value="0x00002136" />
        <message message="$(string.msg_0x2137)" symbol="SAMP_USER_COMMENT_DSMA" value="0x00002137" />
        <message message="$(string.msg_0x2138)" symbol="SAMP_ALIAS_COMMENT_DSMA" value="0x00002138" />
        <message message="$(string.msg_0x2139)" symbol="SAMP_ALIAS_NAME_STORAGE_REPLICA_ADMINS" value="0x00002139" />
        <message message="$(string.msg_0x213A)" symbol="SAMP_ALIAS_COMMENT_STORAGE_REPLICA_ADMINS" value="0x0000213A" />
        <message message="$(string.msg_0x213B)" symbol="SAMP_GROUP_NAME_KEY_ADMINS" value="0x0000213B" />
        <message message="$(string.msg_0x213C)" symbol="SAMP_GROUP_COMMENT_KEY_ADMINS" value="0x0000213C" />
        <message message="$(string.msg_0x213D)" symbol="SAMP_GROUP_NAME_ENTERPRISE_KEY_ADMINS" value="0x0000213D" />
        <message message="$(string.msg_0x213E)" symbol="SAMP_GROUP_COMMENT_ENTERPRISE_KEY_ADMINS" value="0x0000213E" />
        <message message="$(string.msg_0x400C)" symbol="SAMMSG_KRBTGT_RENAMED" value="0x0000400C" />
        <message message="$(string.msg_0x4200)" symbol="SAMMSG_AUDIT_ENABLED_LOCAL_GROUP_TO_ENABLED_UNIVERSAL_GROUP" value="0x00004200" />
        <message message="$(string.msg_0x4201)" symbol="SAMMSG_AUDIT_ENABLED_LOCAL_GROUP_TO_DISABLED_LOCAL_GROUP" value="0x00004201" />
        <message message="$(string.msg_0x4202)" symbol="SAMMSG_AUDIT_ENABLED_LOCAL_GROUP_TO_DISABLED_UNIVERSAL_GROUP" value="0x00004202" />
        <message message="$(string.msg_0x4203)" symbol="SAMMSG_AUDIT_ENABLED_GLOBAL_GROUP_TO_ENABLED_UNIVERSAL_GROUP" value="0x00004203" />
        <message message="$(string.msg_0x4204)" symbol="SAMMSG_AUDIT_ENABLED_GLOBAL_GROUP_TO_DISABLED_GLOBAL_GROUP" value="0x00004204" />
        <message message="$(string.msg_0x4205)" symbol="SAMMSG_AUDIT_ENABLED_GLOBAL_GROUP_TO_DISABLED_UNIVERSAL_GROUP" value="0x00004205" />
        <message message="$(string.msg_0x4206)" symbol="SAMMSG_AUDIT_ENABLED_UNIVERSAL_GROUP_TO_ENABLED_LOCAL_GROUP" value="0x00004206" />
        <message message="$(string.msg_0x4207)" symbol="SAMMSG_AUDIT_ENABLED_UNIVERSAL_GROUP_TO_ENABLED_GLOBAL_GROUP" value="0x00004207" />
        <message message="$(string.msg_0x4208)" symbol="SAMMSG_AUDIT_ENABLED_UNIVERSAL_GROUP_TO_DISABLED_LOCAL_GROUP" value="0x00004208" />
        <message message="$(string.msg_0x4209)" symbol="SAMMSG_AUDIT_ENABLED_UNIVERSAL_GROUP_TO_DISABLED_GLOBAL_GROUP" value="0x00004209" />
        <message message="$(string.msg_0x420A)" symbol="SAMMSG_AUDIT_ENABLED_UNIVERSAL_GROUP_TO_DISABLED_UNIVERSAL_GROUP" value="0x0000420A" />
        <message message="$(string.msg_0x420B)" symbol="SAMMSG_AUDIT_DISABLED_LOCAL_GROUP_TO_ENABLED_LOCAL_GROUP" value="0x0000420B" />
        <message message="$(string.msg_0x420C)" symbol="SAMMSG_AUDIT_DISABLED_LOCAL_GROUP_TO_ENABLED_UNIVERSAL_GROUP" value="0x0000420C" />
        <message message="$(string.msg_0x420D)" symbol="SAMMSG_AUDIT_DISABLED_LOCAL_GROUP_TO_DISABLED_UNIVERSAL_GROUP" value="0x0000420D" />
        <message message="$(string.msg_0x420E)" symbol="SAMMSG_AUDIT_DISABLED_GLOBAL_GROUP_TO_ENABLED_GLOBAL_GROUP" value="0x0000420E" />
        <message message="$(string.msg_0x420F)" symbol="SAMMSG_AUDIT_DISABLED_GLOBAL_GROUP_TO_ENABLED_UNIVERSAL_GROUP" value="0x0000420F" />
        <message message="$(string.msg_0x4210)" symbol="SAMMSG_AUDIT_DISABLED_GLOBAL_GROUP_TO_DISABLED_UNIVERSAL_GROUP" value="0x00004210" />
        <message message="$(string.msg_0x4211)" symbol="SAMMSG_AUDIT_DISABLED_UNIVERSAL_GROUP_TO_ENABLED_LOCAL_GROUP" value="0x00004211" />
        <message message="$(string.msg_0x4212)" symbol="SAMMSG_AUDIT_DISABLED_UNIVERSAL_GROUP_TO_ENABLED_GLOBAL_GROUP" value="0x00004212" />
        <message message="$(string.msg_0x4213)" symbol="SAMMSG_AUDIT_DISABLED_UNIVERSAL_GROUP_TO_ENABLED_UNIVERSAL_GROUP" value="0x00004213" />
        <message message="$(string.msg_0x4214)" symbol="SAMMSG_AUDIT_DISABLED_UNIVERSAL_GROUP_TO_DISABLED_LOCAL_GROUP" value="0x00004214" />
        <message message="$(string.msg_0x4215)" symbol="SAMMSG_AUDIT_DISABLED_UNIVERSAL_GROUP_TO_DISABLED_GLOBAL_GROUP" value="0x00004215" />
        <message message="$(string.msg_0x4216)" symbol="SAMMSG_AUDIT_MEMBER_ACCOUNT_NAME_NOT_AVAILABLE" value="0x00004216" />
        <message message="$(string.msg_0x4217)" symbol="SAMMSG_AUDIT_ACCOUNT_ENABLED" value="0x00004217" />
        <message message="$(string.msg_0x4218)" symbol="SAMMSG_AUDIT_ACCOUNT_DISABLED" value="0x00004218" />
        <message message="$(string.msg_0x4219)" symbol="SAMMSG_AUDIT_ACCOUNT_CONTROL_CHANGE" value="0x00004219" />
        <message message="$(string.msg_0x421B)" symbol="SAMMSG_AUDIT_ACCOUNT_NAME_CHANGE" value="0x0000421B" />
        <message message="$(string.msg_0x421C)" symbol="SAMMSG_AUDIT_DOMAIN_POLICY_CHANGE_PWD" value="0x0000421C" />
        <message message="$(string.msg_0x421D)" symbol="SAMMSG_AUDIT_DOMAIN_POLICY_CHANGE_LOGOFF" value="0x0000421D" />
        <message message="$(string.msg_0x421E)" symbol="SAMMSG_AUDIT_DOMAIN_POLICY_CHANGE_OEM" value="0x0000421E" />
        <message message="$(string.msg_0x421F)" symbol="SAMMSG_AUDIT_DOMAIN_POLICY_CHANGE_REPLICATION" value="0x0000421F" />
        <message message="$(string.msg_0x4220)" symbol="SAMMSG_AUDIT_DOMAIN_POLICY_CHANGE_SERVERROLE" value="0x00004220" />
        <message message="$(string.msg_0x4221)" symbol="SAMMSG_AUDIT_DOMAIN_POLICY_CHANGE_STATE" value="0x00004221" />
        <message message="$(string.msg_0x4222)" symbol="SAMMSG_AUDIT_DOMAIN_POLICY_CHANGE_LOCKOUT" value="0x00004222" />
        <message message="$(string.msg_0x4223)" symbol="SAMMSG_AUDIT_DOMAIN_POLICY_CHANGE_MODIFIED" value="0x00004223" />
        <message message="$(string.msg_0x4224)" symbol="SAMMSG_AUDIT_DOMAIN_POLICY_CHANGE_DOMAINMODE" value="0x00004224" />
        <message message="$(string.msg_0x4225)" symbol="SAMMSG_AUDIT_BASIC_TO_QUERY_GROUP" value="0x00004225" />
        <message message="$(string.msg_0x4226)" symbol="SAMMSG_AUDIT_QUERY_TO_BASIC_GROUP" value="0x00004226" />
      </messageTable>
    </events>
  </instrumentation>
  <configuration xmlns="urn:schemas-microsoft-com:asm.v3" xmlns:asmv2="urn:schemas-microsoft-com:asm.v3" xmlns:wcm="http://schemas.microsoft.com/WMIConfig/2002/State">
    <configurationSchema>
      <xsd:schema xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns="Microsoft-Windows-Directory-Services-SAM" targetNamespace="Microsoft-Windows-Directory-Services-SAM">
        <xsd:element name="SamReplicatePasswordsUrgently" type="xsd:boolean" wcm:description="Configures system to replicate password deltas urgently within a site" wcm:displayName="SamReplicatePasswordsUrgently" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="SamDisableSingleObjectRepl" type="xsd:boolean" wcm:description="Configures system to not replication down updated information from the PDC during logon failures" wcm:displayName="SamDisableSingleObjectRepl" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="IgnoreGCFailures" type="xsd:boolean" wcm:description="Configures system to not fail logons if no GC is present" wcm:displayName="IgnoreGCFailures" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element default="true" name="NoLmHash" type="xsd:boolean" wcm:description="Configures system to not store LM hash of password." wcm:displayName="NoLmHash" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="SamNoGcLogonEnforceNTLMCheck" type="xsd:boolean" wcm:description="Configures system to user NTLM logon information to determine site membership for the no GC logon configuration." wcm:displayName="SamNoGcLogonEnforceNTLMCheck" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="SamNoGcLogonEnforceKerberosIpCheck" type="xsd:boolean" wcm:description="Configures system user Kerberos logon information to determine site membership for the no GC logon configuration" wcm:displayName="SamNoGcLogonEnforceKerberosIpCheck" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="ForceGuest" type="xsd:boolean" wcm:description="Configures system such that network authentication is always in the Guest account context" wcm:displayName="ForceGuest" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="SamAccountLockoutTestMode" type="xsd:boolean" wcm:description="Configures system such that bad password count is updated in AD but not the user account control bit to lockout the account." wcm:displayName="SamAccountLockoutTestMode" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="RestrictAnonymous" type="xsd:unsignedInt" wcm:description="0 - Disabled. Anonymous users are not restricted.  1 - Enabled. Users who log on anonymously (also known as null session connections) cannot display lists of domain user names or share names. Also, these users can not view security permissions, and they can not use all of the features of File Explorer, Local Users and Groups, and other programs that enumerate users or shares.  2 - Anonymous users have no access without explicit anonymous permissions." wcm:displayName="RestrictAnonymous" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="RestrictAnonymousSam" type="xsd:boolean" wcm:description="If enabled requires client to be an authenticated user to get DOMAIN_LIST_ACCOUNTS or GROUP_LIST_MEMBERS or ALIAS_LIST_MEMBERS access." wcm:displayName="RestrictAnonymousSam" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="RestrictRemoteSam" type="xsd:string" wcm:description="Security Descriptor Definition Language (SDDL) string allows or blocks remote access to the SAM. If the value is missing or incorrect, remote access is allowed. This SDDL does not change the access given to a remote user." wcm:displayName="RestrictRemoteSam" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_SZ" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="ExtendedSidEmulationMode" type="xsd:unsignedInt" wcm:description="Until large SID support is supported, applications can put a server in 'Emulation Mode' via a registry key. This causes the SAM server to behave as if the account domain is in ExtendedSid mode but the account doesn't really allocate SID's in a large sid fashion.  This emulation is controlled by the registry key ExtendedSidEmulationMode: a value of 1 indicates compatibility mode 1; a value of 2 indicates compatibility mode 2; any other value is ignored." wcm:displayName="ExtendedSidEmulationMode" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="SamLogLevel" type="xsd:unsignedInt" wcm:description="Logging mask to enable SAM diagnostic logging to %windir%\debug\sam.log." wcm:displayName="SamLogLevel" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="SamRestrictOwfPasswordChange" type="xsd:unsignedInt" wcm:description="0 - old behavior, client can change password through OWF password change API, and the new password remains unexpired.  1 - Windows XP and Windows Server 2003 default behavior, client can change password through OWF password change API (SamrChangePasswordUser), but the password expires immediately.  2 - more secure behavior, client cannot use OWF password change API. This API (SamrChangePasswordUser) will be totally locked down." wcm:displayName="SamRestrictOwfPasswordChange" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="MaxSamConnections" type="xsd:unsignedInt" wcm:description="The maximum allowable number of active clients." wcm:displayName="MaxSamConnections" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="dsrmAdminLogonBehavior" type="xsd:unsignedInt" wcm:description="0 - default behavior, DSRM account only allowed to logon in DSRM mode, 1 - DSRM account can logon when DS is stopped or in DSRM, 2 - DSRM account can logon all the time." wcm:displayName="dsrmAdminLogonBehavior" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="TraceSamEventInDetail" type="xsd:unsignedInt" wcm:description="Set level of trace detail in SAM trace events." wcm:displayName="TraceSamEventInDetail" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="NetWareClientSupport" type="xsd:boolean" wcm:description="Control NetWare protocol sequence support." wcm:displayName="NetWareClientSupport" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="AppletalkClientSupport" type="xsd:boolean" wcm:description="Control AppleTalk protocol sequence support." wcm:displayName="AppletalkClientSupport" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="VinesClientSupport" type="xsd:boolean" wcm:description="Control Banyan Vines protocol sequence support." wcm:displayName="VinesClientSupport" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="AvoidPdcOnWan" type="xsd:boolean" wcm:description="Avoid retry of authentication at PDC if it's not in our site.  Also avoid updating logon statistics at the PDC." wcm:displayName="AvoidPdcOnWan" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="UpdateLastLogonTSByMinute" type="xsd:boolean" wcm:description="d__th.obj.amd64fre_ds_ds_src_sam_server_mbs_microsoft-windows-directory-services-sam_objfre_amd64_samsrv.man.temp1.missingResource.config_description_UpdateLastLogonTSByMinute" wcm:displayName="UpdateLastLogonTSByMinute" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="RID_Block_Size" type="xsd:unsignedInt" wcm:description="Enables setting RID pool sizes greater than the default 500, commonly used for outward facing directories with high volume account creation and low replica count." wcm:displayName="RID Block Size" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\RID Values')" wcm:legacyName="RID Block Size" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="Notification_Packages" type="wcm:multiString" wcm:description="List of package module names, without extension, that should be loaded for password change notification callouts" wcm:displayName="Notification Packages" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyName="Notification Packages" wcm:legacyType="REG_MULTI_SZ" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="ProductType" type="xsd:unsignedInt" wcm:description="Cached product type ID maintained by SAM" wcm:displayName="ProductType" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyName="ProductType" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="SamDisableListenOnTCP" type="xsd:unsignedInt" wcm:description="Controls whether SAM service listens on TCP." wcm:displayName="SamDisableListenOnTCP" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
      </xsd:schema>
    </configurationSchema>
    <metadata />
  </configuration>
</assembly>