Advertisement
allan

NPS-RADIUS Event IDs

Jun 24th, 2022
175
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.56 KB | None | 0 0
  1. Microsoft Network Policy Server (NPS) Event IDs
  2.  
  3. Ref: https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-network-policy-server
  4.  
  5. 13: A RADIUS message was received from the invalid RADIUS client IP address <ip>.
  6. 17: An Access-Request message was received from RADIUS client <ip> without a Message-Authenticator attribute when a Message-Authenticator attribute is required. Verify the configuration of the RADIUS client in the Network Policy Server snap-in (the "Client must always send the Message-Authenticator attribute in the request" checkbox) and the configuration of the network access server.
  7. 4400: A LDAP connection with domain controller <hostname> for domain <name> is established.
  8. 4401: Domain controller <hostname> for domain <name> is not responsive. NPS switches to other DCs.
  9. 4402: There is no domain controller available for domain <name>.
  10. 6272: Network Policy Server granted access to a user.
  11. 6273: Network Policy Server denied access to a user.
  12. 6274: Network Policy Server discarded the request for a user.
  13. 6275: Network Policy Server discarded the accounting request for a user.
  14. 6276: Network Policy Server quarantined a user.
  15. 6277: Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy.
  16. 6278: Network Policy Server granted full access to a user because the host met the defined health policy.
  17. 6279: Network Policy Server locked the user account due to repeated failed authentication attempts.
  18. 6280: Network Policy Server unlocked the user account.
  19.  
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement