Event 6273 with reason code 22 — "The client could not be authenticated because the Extensible Authentication Protocol (EAP) Type cannot be processed by the server." The EAP negotiation itself failed: the method the client proposed is not enabled (or not usable) in the matched network policy.
Reason code 22
NPS 6273 reason 22: EAP type cannot be processed
What it means
Common causes
EAP method mismatch: client configured for EAP-TLS while the policy only offers PEAP, or the other way round.
The policy's EAP method is unusable because its server certificate is missing, expired, or lacks the Server Authentication EKU — PEAP/EAP-TLS cannot start without it.
The request matched a different network policy than you think, one with different EAP settings.
How to fix it
Compare the client's 802.1X profile EAP method with the Constraints > Authentication Methods of the network policy named in the event.
Open the network policy's EAP configuration and confirm a valid server certificate is selected; renew it if expired and re-select it in the policy (NPS does not always follow renewals automatically).
Check which policy actually matched (Network Policy Name field in the event) — reorder or tighten conditions if the wrong one matched.