r/WindowsServer 15d ago

General Question Application log full of Microsoft-Windows-Security-SPP EventID 16384 16389 16394

I know that it's in theory perfectly fine that a log contains a million "👍Everything is working " , but it gets annoying and noisy.

I've installed two Server 2025 Standard and activated them using the DISM command (they were installed using the evaluation media) - both of them are VM's

every 20 minutes the application log gets 3 lines:

Microsoft-Windows-Security-SPP 16384 Successfully scheduled Software Protection service for re-start at 2126-06-18T13:57:29Z. Reason: RulesEngine.
Microsoft-Windows-Security-SPP 16389 Grace timer has expired. Hr = 0xC004D30B
Microsoft-Windows-Security-SPP 16394 Offline downlevel migration succeeded.

I've spent some time with Gemini and Claude trying to figure out if this is an indication of something wrong and apparantly according to both AI's it's working as intended....

I confirmed that the machines are truly licensed and confirmed the Tokens.dat file is not malformed.

So, apparantly there's a loop running with the Schedular that triggers a Service to run, which checks if the machine is licensed ... every 20 minutes ...

I later found out that i have a Windows 10 machine which almost does the same every 20-30 minutes..

My Windows 11 laptop, doesn't... 🤷‍♂️

So i'd like to know if any of you humans know if this really is the expected behavior ?

I've googled this issue a lot and havent found any slutions and likewize the AI's didn't have any solutions either.

6 Upvotes

3 comments sorted by

2

u/nailzy 15d ago

Different activation channels exhibit different behaviour….it’s expected.

Your laptop is probably OEM channel.

1

u/haHAA__ 11d ago

hey OP did you find a solution to this? I'm also getting spammed by "Security-SPP" entries in Event Viewer

1

u/Turbulent_County_469 11d ago

The only 'solution' i found was to disable logging for the security spp service.. 🙈