Windows Security Log Event ID 6276

Operating Systems Windows 2008 R2 and 7
Windows 2012 R2 and 8.1
Windows 2016 and 10
Windows Server 2019 and 2022
 • Subcategory
 • Network Policy Server
Type Success
Corresponding events
in Windows 2003
and before

6276: Network Policy Server quarantined a user

On this page

I haven't been able to produce this event. Have you? If so, please start a discussion (see above) and post a sample along with any comments you may have! Don't forget to sanitize any private information.

Free Security Log Resources by Randy

Supercharger Free Edition

Supercharger's built-in Xpath filters leave the noise behind.



Examples of 6276

Network Policy Server quarantined a user.

Contact the Network Policy Server administrator for more information.


   Security ID:   %1
   Account Name:   %2
   Account Domain:   %3
   Fully Qualified Account Name: %4

Client Machine:

   Security ID:   %5
   Account Name:   %6
   Fully Qualified Account Name: %7
   OS-Version:   %8
   Called Station Identifier:  %9
   Calling Station Identifier:  %10


   NAS IPv4 Address:  %11
   NAS IPv6 Address:  %12
   NAS Identifier:   %13
   NAS Port-Type:   %14
   NAS Port:   %15

RADIUS Client:

   Client Friendly Name:  %16
   Client IP Address:   %17

Authentication Details:

   Proxy Policy Name:  %18
   Network Policy Name:  %19
   Authentication Provider:  %20
   Authentication Server:  %21
   Authentication Type:  %22
   EAP Type:   %23
   Account Session Identifier:  %24

Quarantine Information:

   Result:    %25
   Extended-Result:   %26
   Session Identifier:   %27
   Help URL:   %28
   System Health Validator Result(s): %29

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection


Additional Resources