EventSentry
  • System32
  • Sysmon
  • Events
  • Compliance
  • Validator
  • TLS/SSL
  • GeoIP
  • Tools


Windows Security Events



Audit Category
  • Logon/Logoff (9)
Operating Systems
  • Windows 10 (9)
  • Windows 11 (9)
  • Windows 2008 (9)
  • Windows 2008 R2 (9)
  • Windows 2012 (9)
  • Windows 2012 R2 (9)
  • Windows 2016 (9)
  • Windows 2019 (9)
  • Windows 2022 (9)
  • Windows 2025 (9)
  • Windows 7 (9)
  • Windows 8 (9)
  • Windows 8.1 (9)
  • Windows Vista (9)
Tags
  • Audit Failure (9)
  • Audit Success (9)
Auditing
  • Conditional (9)
Volume
    Audit Subcategory
    • Network Policy Server (9)

    AppLocker
    • All AppLocker events
    EventSentry
    • All EventSentry events
    Security
    • All Windows Security events
    Sysmon
    • All Sysmon events
    IDEvent Description
    6272 Network Policy Server granted access to a user.
    Audit Success, Audit Failure
    6273 Network Policy Server denied access to a user.
    Audit Success, Audit Failure
    6274 Network Policy Server discarded the request for a user.
    Audit Success, Audit Failure
    6275 Network Policy Server discarded the accounting request for a user.
    Audit Success, Audit Failure
    6276 Network Policy Server quarantined a user.
    Audit Success, Audit Failure
    6277 Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy.
    Audit Success, Audit Failure
    6278 Network Policy Server granted full access to a user because the host met the defined health policy.
    Audit Success, Audit Failure
    6279 Network Policy Server locked the user account due to repeated failed authentication attempts.
    Audit Success, Audit Failure
    6280 Network Policy Server unlocked the user account.
    Audit Success, Audit Failure



    © netikus.net ltd 2002-2026 | EventSentry Events | Codes | Sysmon | STIG | AppLocker | Privacy Policy