allan icon

NPS-RADIUS Event IDs

allan | PRO | 06/24/22 02:32:17 PM UTC | 0 ⭐ | 528 👁️ | Never ⏰ | []
text |

1.56 KB

|

None

|

0 👍

/

0 👎

Microsoft Network Policy Server (NPS) Event IDs
 Ref: https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-network-policy-server
   13: A RADIUS message was received from the invalid RADIUS client IP address <ip>.
  17: An Access-Request message was received from RADIUS client <ip> without a Message-Authenticator attribute when a Message-Authenticator attribute is required. Verify the configuration of the RADIUS client in the Network Policy Server snap-in (the "Client must always send the Message-Authenticator attribute in the request" checkbox) and the configuration of the network access server.
4400: A LDAP connection with domain controller <hostname> for domain <name> is established.
4401: Domain controller <hostname> for domain <name> is not responsive. NPS switches to other DCs.
4402: There is no domain controller available for domain <name>.
6272: Network Policy Server granted access to a user.
6273: Network Policy Server denied access to a user.
6274: Network Policy Server discarded the request for a user.
6275: Network Policy Server discarded the accounting request for a user.
6276: Network Policy Server quarantined a user.
6277: Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy.
6278: Network Policy Server granted full access to a user because the host met the defined health policy.
6279: Network Policy Server locked the user account due to repeated failed authentication attempts.
6280: Network Policy Server unlocked the user account.
 

Comments

  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎