Microsoft Network Policy Server (NPS) Event IDs Ref: https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-network-policy-server 13: A RADIUS message was received from the invalid RADIUS client IP address . 17: An Access-Request message was received from RADIUS client without a Message-Authenticator attribute when a Message-Authenticator attribute is required. Verify the configuration of the RADIUS client in the Network Policy Server snap-in (the "Client must always send the Message-Authenticator attribute in the request" checkbox) and the configuration of the network access server. 4400: A LDAP connection with domain controller for domain is established. 4401: Domain controller for domain is not responsive. NPS switches to other DCs. 4402: There is no domain controller available for domain . 6272: Network Policy Server granted access to a user. 6273: Network Policy Server denied access to a user. 6274: Network Policy Server discarded the request for a user. 6275: Network Policy Server discarded the accounting request for a user. 6276: Network Policy Server quarantined a user. 6277: Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy. 6278: Network Policy Server granted full access to a user because the host met the defined health policy. 6279: Network Policy Server locked the user account due to repeated failed authentication attempts. 6280: Network Policy Server unlocked the user account.