NPS Reason Codes
10rows
10rows with meaning
1lookups that use it
Livestatus
The reason codes Network Policy Server records when it turns a RADIUS request down. A failed VPN or Wi-Fi sign-in reduces to one of these once the request reaches the policy server.
This table decodes 10 codes.
SparkLogs decodes these codes on every event that carries one, regardless of feed. The Windows Security event log feed reads these codes while curating an event.
How to read this
Codes are listed in numeric order. Windows publishes no constant for this space, so Name is the short label SparkLogs puts on the event, and it is what a question groups by. The last column is our one-line summary of what the code means in plain words.
Codes 8 to 262
| Code | Name | What it means |
|---|---|---|
8 | account_not_found | the account named in the RADIUS User-Name attribute does not exist |
16 | bad_credentials | a user credentials mismatch: the name maps to no account, or the password was wrong |
21 | extension_rejected | an extension library installed on the server rejected the connection request |
23 | eap_error | an error occurred during the server use of the Extensible Authentication Protocol |
36 | account_locked_out | the attempts exceeded the account lockout threshold in account lockout policy |
48 | no_network_policy_match | the request matched no configured network policy and was denied |
49 | no_request_policy_match | the request matched no configured connection request policy and was denied |
65 | dialin_access_denied | the network access permission in the account dial-in properties is set to deny |
66 | auth_method_not_permitted | the matching network policy does not enable the authentication method used, guest authentication included |
262 | unverified_signature | the message was discarded as incomplete with its signature unverified |
Ask about these codes
Connect your AI and ask in plain language, or open the same events in Explore.