Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Microsoft Network Policy Server (NPS) Event IDs
- Ref: https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-network-policy-server
- 13: A RADIUS message was received from the invalid RADIUS client IP address <ip>.
- 17: An Access-Request message was received from RADIUS client <ip> without a Message-Authenticator attribute when a Message-Authenticator attribute is required. Verify the configuration of the RADIUS client in the Network Policy Server snap-in (the "Client must always send the Message-Authenticator attribute in the request" checkbox) and the configuration of the network access server.
- 4400: A LDAP connection with domain controller <hostname> for domain <name> is established.
- 4401: Domain controller <hostname> for domain <name> is not responsive. NPS switches to other DCs.
- 4402: There is no domain controller available for domain <name>.
- 6272: Network Policy Server granted access to a user.
- 6273: Network Policy Server denied access to a user.
- 6274: Network Policy Server discarded the request for a user.
- 6275: Network Policy Server discarded the accounting request for a user.
- 6276: Network Policy Server quarantined a user.
- 6277: Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy.
- 6278: Network Policy Server granted full access to a user because the host met the defined health policy.
- 6279: Network Policy Server locked the user account due to repeated failed authentication attempts.
- 6280: Network Policy Server unlocked the user account.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement