6279 Security log · Network Policy Server high severity low volume

Windows Event ID 6279 — Network Policy Server locked the user account due to repeated failed authentication attempts

NPS locked an account after too many VPN authentication failures.

Why event 6279 matters

VPN-targeted brute force sufficient to cause account lockout. Very high signal — indicates sustained attack against the VPN.

How to detect it

Alert on every occurrence. Treat as active attack — correlate with 6273 events.

Log source
Security
Advanced Audit Policy — enable the 'Network Policy Server' subcategory (Success and/or Failure).
Fields to pivot on
SubjectUserNameTargetUserNameLogonTypeIpAddressWorkstationName

MITRE ATT&CK mapping

Tactic Technique
Credential Access Brute Force (T1110)

Detection queries

Starting points — adapt the log source, projected fields and thresholds for your environment.

Sentinel / Defender KQL
SecurityEvent
| where EventID == 6279   // Network Policy Server locked the user account due to repeated failed authentication attempts
| project TimeGenerated, Computer, SubjectUserName, TargetUserName, LogonType, IpAddress, WorkstationName
| sort by TimeGenerated desc
Splunk SPL
index=* sourcetype="WinEventLog:Security" EventCode=6279
| stats count earliest(_time) as first_seen latest(_time) as last_seen by ComputerName
| sort - count   `# Network Policy Server locked the user account due to repeated failed authentication attempts — add EventData fields: SubjectUserName, TargetUserName, LogonType, IpAddress`
Hunt event 6279 in Sentinel/Defender →
Build a KQL query for this event in the KQL Query Builder.
Search all event IDs →
Open the interactive Windows Event ID lookup.

Related Network Policy Server events

6272 Network Policy Server granted access to a user 6273 Network Policy Server denied access to a user 6274 Network Policy Server discarded the request for a user 6278 Network Policy Server granted full access to a user because the host met the defined health policy 6280 Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy

Frequently asked questions

What is Windows Event ID 6279?

Network Policy Server locked the user account due to repeated failed authentication attempts. NPS locked an account after too many VPN authentication failures.

Which log records event 6279?

Event 6279 is written to the Security channel by Microsoft-Windows-Security-Auditing. Advanced Audit Policy — enable the 'Network Policy Server' subcategory (Success and/or Failure).

What MITRE ATT&CK techniques map to event 6279?

Event 6279 is associated with: Brute Force (T1110).

How do you detect activity around event 6279?

Alert on every occurrence. Treat as active attack — correlate with 6273 events.