← Event ID reference
36887

A fatal TLS alert was received from the remote endpoint

  • Log: System
  • Source: Schannel
  • TLS & certificates
  • Info

What it means

A TLS connection failed and the other side sent an alert code, for example 40 (handshake failure) or 70 (protocol version).

Why it matters

Usually noise, but bursts after disabling old TLS versions show which systems still need them.

What to do

  • Look up the alert code.
  • Find the remote system and update its TLS settings.

Find it with PowerShell

Get-WinEvent -MaxEvents 20 -FilterHashtable @{
  LogName = 'System'; Id = 36887
} | Select-Object TimeCreated, ProviderName, Message

Add -ComputerName SERVER to query another machine. Other event sources can reuse the same ID number, so check the ProviderName column.

Seeing a lot of these? We can investigate, or alert you automatically through our monitoring.

Talk to us