6280 Security log · Network Policy Server medium severity low volume

Windows Event ID 6280 — Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy

NPS granted restricted access (probation) — device failed health check.

Why event 6280 matters

Indicates non-compliant device on network. May be a compromised or unmanaged endpoint. Correlate with other events from same device to assess threat.

How to detect it

Alert: known-managed devices placed in probation (unexpected non-compliance = possible compromise). Alert: new unknown devices in probation.

Log source
Security
Advanced Audit Policy — enable the 'Network Policy Server' subcategory (Success and/or Failure).
Fields to pivot on
SubjectUserNameTargetUserNameLogonTypeIpAddressWorkstationName

Detection queries

Starting points — adapt the log source, projected fields and thresholds for your environment.

Sentinel / Defender KQL
SecurityEvent
| where EventID == 6280   // Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy
| project TimeGenerated, Computer, SubjectUserName, TargetUserName, LogonType, IpAddress, WorkstationName
| sort by TimeGenerated desc
Splunk SPL
index=* sourcetype="WinEventLog:Security" EventCode=6280
| stats count earliest(_time) as first_seen latest(_time) as last_seen by ComputerName
| sort - count   `# Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy — add EventData fields: SubjectUserName, TargetUserName, LogonType, IpAddress`
Hunt event 6280 in Sentinel/Defender →
Build a KQL query for this event in the KQL Query Builder.
Search all event IDs →
Open the interactive Windows Event ID lookup.

Related Network Policy Server events

6272 Network Policy Server granted access to a user 6273 Network Policy Server denied access to a user 6274 Network Policy Server discarded the request for a user 6278 Network Policy Server granted full access to a user because the host met the defined health policy 6279 Network Policy Server locked the user account due to repeated failed authentication attempts

Frequently asked questions

What is Windows Event ID 6280?

Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy. NPS granted restricted access (probation) — device failed health check.

Which log records event 6280?

Event 6280 is written to the Security channel by Microsoft-Windows-Security-Auditing. Advanced Audit Policy — enable the 'Network Policy Server' subcategory (Success and/or Failure).

How do you detect activity around event 6280?

Alert: known-managed devices placed in probation (unexpected non-compliance = possible compromise). Alert: new unknown devices in probation.