Windows Security Log Event ID 6276

Operating Systems Windows 2008 R2 and 7
Windows 2012 R2 and 8.1
Windows 2016 and 10
Windows Server 2019 and 2022
 • Subcategory
 • Network Policy Server
Type Success
Corresponding events
in Windows 2003
and before

6276: Network Policy Server quarantined a user

On this page

I haven't been able to produce this event. Have you? If so, please start a discussion (see above) and post a sample along with any comments you may have! Don't forget to sanitize any private information.

Free Security Log Resources by Randy

Supercharger Enterprise

Load Balancing for Windows Event Collection


Examples of 6276

Network Policy Server quarantined a user.

Contact the Network Policy Server administrator for more information.


   Security ID:   %1
   Account Name:   %2
   Account Domain:   %3
   Fully Qualified Account Name: %4

Client Machine:

   Security ID:   %5
   Account Name:   %6
   Fully Qualified Account Name: %7
   OS-Version:   %8
   Called Station Identifier:  %9
   Calling Station Identifier:  %10


   NAS IPv4 Address:  %11
   NAS IPv6 Address:  %12
   NAS Identifier:   %13
   NAS Port-Type:   %14
   NAS Port:   %15

RADIUS Client:

   Client Friendly Name:  %16
   Client IP Address:   %17

Authentication Details:

   Proxy Policy Name:  %18
   Network Policy Name:  %19
   Authentication Provider:  %20
   Authentication Server:  %21
   Authentication Type:  %22
   EAP Type:   %23
   Account Session Identifier:  %24

Quarantine Information:

   Result:    %25
   Extended-Result:   %26
   Session Identifier:   %27
   Help URL:   %28
   System Health Validator Result(s): %29

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection


Additional Resources