Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

Event ID 63 may be logged in the Application log after you install Windows Server 2008


View products that this article applies to.

Symptoms

After you install Windows Server 2008, an event ID 63 that resembles the following event may be logged in the Application log:

Log Name: Application
Source: WMI
Date: Date
Time: Time
Event ID: 63
Level: Warning
Description:
A provider, WmiPerfClass, has been registered in the Windows Management Instrumentation namespace root\cimv2 to use the Local System account.

This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

↑ Back to the top


Cause

This issue occurs because the Windows Management Instrumentation (WMI) provider host process runs under the privileged Local System account. Because the WmiPerfClass provider is a trusted source, you can safely ignore this event.

↑ Back to the top


Status

This behavior is by design.

↑ Back to the top


Keywords: KB952574, kbprb, kbtshoot, kbexpertiseinter

↑ Back to the top

Article Info
Article ID : 952574
Revision : 1
Created on : 5/12/2008
Published on : 5/12/2008
Exists online : False
Views : 486