Skip to main content

NPS Reason Codes

10rows
10rows with meaning
1lookups that use it
Livestatus

The reason codes Network Policy Server records when it turns a RADIUS request down. A failed VPN or Wi-Fi sign-in reduces to one of these once the request reaches the policy server.

This table decodes 10 codes.

SparkLogs decodes these codes on every event that carries one, regardless of feed. The Windows Security event log feed reads these codes while curating an event.

How to read this

Codes are listed in numeric order. Windows publishes no constant for this space, so Name is the short label SparkLogs puts on the event, and it is what a question groups by. The last column is our one-line summary of what the code means in plain words.

Codes 8 to 262

CodeNameWhat it means
8account_not_foundthe account named in the RADIUS User-Name attribute does not exist
16bad_credentialsa user credentials mismatch: the name maps to no account, or the password was wrong
21extension_rejectedan extension library installed on the server rejected the connection request
23eap_erroran error occurred during the server use of the Extensible Authentication Protocol
36account_locked_outthe attempts exceeded the account lockout threshold in account lockout policy
48no_network_policy_matchthe request matched no configured network policy and was denied
49no_request_policy_matchthe request matched no configured connection request policy and was denied
65dialin_access_deniedthe network access permission in the account dial-in properties is set to deny
66auth_method_not_permittedthe matching network policy does not enable the authentication method used, guest authentication included
262unverified_signaturethe message was discarded as incomplete with its signature unverified

Ask about these codes

Connect your AI and ask in plain language, or open the same events in Explore.