Windows Security Log Event ID 6279

Operating Systems Windows 2008 R2 and 7
Windows 2012 R2 and 8.1
Windows 2016 and 10
Windows Server 2019 and 2022
Category
 • Subcategory
Logon/Logoff
 • Network Policy Server
Type Success
Corresponding events
in Windows 2003
and before
 

6279: Network Policy Server locked the user account due to repeated failed authentication attempts

On this page

I haven't been able to produce this event. Have you? If so, please start a discussion (see above) and post a sample along with any comments you may have! Don't forget to sanitize any private information.

Free Security Log Resources by Randy

Setup PowerShell Audit Log Forwarding in 4 Minutes

 

Examples of 6279

Network Policy Server locked the user account due to repeated failed authentication attempts.

User:

   Security ID:   %1
   Account Name:   %2
   Account Domain:   %3
   Fully Qualified Account Name: %4

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection

 

Additional Resources