Reason code 66

NPS 6273 reason 66: authentication method not enabled on the matched policy

Last reviewed 2026-07-18 by the Just Software engineering team ยท also seen as 6273 reason 66, nps reason code 66

What it means

Event 6273 with reason code 66 โ€” "The user attempted to use an authentication method that is not enabled on the matching network policy." Unlike reason 48, a policy did match; the failure is inside its Constraints > Authentication Methods: what the client used is not on the list.

Common causes

  1. Client profile uses PEAP-MSCHAPv2 while the policy only lists Microsoft: Smart Card or other certificate (EAP-TLS), or the reverse.

  2. The policy's 'less secure authentication methods' checkboxes and EAP types list don't include what the NAS/client negotiated.

  3. Two similar policies exist and the request matched the one with the wrong EAP configuration.

How to fix it

  1. Read the Network Policy Name in the event, open that policy > Constraints > Authentication Methods, and compare with the client's configured EAP method.

  2. Align one side: either add the EAP type to the policy or change the client 802.1X profile (deployed via GPO or Intune Wi-Fi/wired profile) to the method the policy expects.

  3. If multiple policies overlap, tighten conditions (groups, NAS Port Type) so requests land on the intended policy.

Frequently asked

What's the difference between reason 48 and reason 66?
Reason 48 means no network policy matched at all. Reason 66 means a policy matched but the client's authentication method isn't enabled in that policy's constraints — fix the EAP method list or the client profile.
An unhandled error has occurred. Reload ๐Ÿ—™