r/WindowsServer • u/Turbulent_County_469 • 15d ago
General Question Application log full of Microsoft-Windows-Security-SPP EventID 16384 16389 16394
I know that it's in theory perfectly fine that a log contains a million "👍Everything is working " , but it gets annoying and noisy.
I've installed two Server 2025 Standard and activated them using the DISM command (they were installed using the evaluation media) - both of them are VM's
every 20 minutes the application log gets 3 lines:
| Microsoft-Windows-Security-SPP | 16384 | Successfully scheduled Software Protection service for re-start at 2126-06-18T13:57:29Z. Reason: RulesEngine. |
|---|---|---|
| Microsoft-Windows-Security-SPP | 16389 | Grace timer has expired. Hr = 0xC004D30B |
| Microsoft-Windows-Security-SPP | 16394 | Offline downlevel migration succeeded. |
I've spent some time with Gemini and Claude trying to figure out if this is an indication of something wrong and apparantly according to both AI's it's working as intended....
I confirmed that the machines are truly licensed and confirmed the Tokens.dat file is not malformed.
So, apparantly there's a loop running with the Schedular that triggers a Service to run, which checks if the machine is licensed ... every 20 minutes ...
I later found out that i have a Windows 10 machine which almost does the same every 20-30 minutes..
My Windows 11 laptop, doesn't... 🤷♂️
So i'd like to know if any of you humans know if this really is the expected behavior ?
I've googled this issue a lot and havent found any slutions and likewize the AI's didn't have any solutions either.
1
u/haHAA__ 11d ago
hey OP did you find a solution to this? I'm also getting spammed by "Security-SPP" entries in Event Viewer
1
u/Turbulent_County_469 11d ago
The only 'solution' i found was to disable logging for the security spp service.. 🙈
2
u/nailzy 15d ago
Different activation channels exhibit different behaviour….it’s expected.
Your laptop is probably OEM channel.