#Requires -Version 5.1 <# JbTecWiz Support Centre -- generated fix script Fault : 802.1X or VPN authentication fails at NPS -- reason codes 16, 23, 48 and 265 Fix : Resolve the authentication method or credential Source: https://jbtecwiz.com/support/srv-app-nps-radius Run as : Elevated PowerShell Expect : 30 minutes Risk : medium Reversible : yes WHEN THIS IS THE RIGHT FIX Reason 16 or 23. HOW TO UNDO IT Directory attribute changes should be recorded before altering them. This script walks the fix one step at a time and asks before each one. Steps with no command are things you do yourself -- it prints those and waits. Run with -DryRun to print without executing. -------------------------------------------------------------------- NO WARRANTY - USE AT YOUR OWN RISK This script is provided by JbTecWiz as-is and with no warranty of any kind, express or implied. You run it entirely at your own risk. JbTecWiz accepts no liability for any loss or damage arising from its use, including but not limited to data loss, downtime, or configuration changes that turn out to be wrong for your system. You are responsible for reading this script before running it, for satisfying yourself that it suits the machine in front of you, and for having a working backup first. Some steps cannot be undone. -------------------------------------------------------------------- #> [CmdletBinding()] param( # Print every step and command without running anything. [switch]$DryRun, # Do not ask before each step. Read the script first if you use this. [switch]$Unattended ) $ErrorActionPreference = 'Stop' $script:Failed = 0 function Write-Rule { param([string]$Text) Write-Host '' Write-Host ('-' * 70) -ForegroundColor DarkGray if ($Text) { Write-Host $Text -ForegroundColor Cyan } } function Show-Prose { param([string]$Text, [string]$Colour = "Gray") if (-not $Text) { return } $words = $Text -split "\s+"; $line = " " foreach ($w in $words) { if (($line.Length + $w.Length) -gt 74) { Write-Host $line -ForegroundColor $Colour; $line = " " } $line += "$w " } if ($line.Trim()) { Write-Host $line -ForegroundColor $Colour } } function Invoke-Step { param( [int]$Number, [string]$Do, [string]$Why, [scriptblock]$Command, [switch]$Manual, [string]$Shell = "powershell" ) Write-Rule " Step $Number of 5" Show-Prose $Do "White" if ($Why) { Write-Host ""; Show-Prose $Why "DarkGray" } if ($Manual) { Write-Host '' Write-Host ' -> Do this yourself, then press Enter to carry on.' -ForegroundColor Yellow if (-not $Unattended -and -not $DryRun) { [void](Read-Host) } return } Write-Host '' foreach ($l in ($Command.ToString().Trim() -split "`n")) { Write-Host (" " + $l.Trim()) -ForegroundColor Green } Write-Host '' if ($DryRun) { Write-Host " (dry run -- not executed)" -ForegroundColor DarkGray; return } if (-not $Unattended) { $a = Read-Host " Run this step? [Y]es / [S]kip / [Q]uit" if ($a -match "^[Qq]") { Write-Host " Stopped at your request."; exit 0 } if ($a -match "^[Ss]") { Write-Host " Skipped." -ForegroundColor DarkGray; return } } try { & $Command } catch { $script:Failed++ Write-Host (" Step $Number failed: " + $_.Exception.Message) -ForegroundColor Red Show-Prose "The rest of the fix may depend on this. Read the write-up before carrying on." "Red" if (-not $Unattended) { $c = Read-Host " Carry on anyway? [y/N]" if ($c -notmatch "^[Yy]") { exit 1 } } } } Write-Rule Write-Host ' 802.1X or VPN authentication fails at NPS -- reason codes 16, 23, 48 and 265' -ForegroundColor White Write-Host ' Resolve the authentication method or credential' -ForegroundColor Cyan Write-Host '' Write-Host ' Risk: medium Reversible 30 minutes' Write-Host '' Show-Prose 'No warranty. Use at your own risk - JbTecWiz accepts no liability. Read it before you run it, and have a backup.' 'DarkYellow' Write-Rule if (-not $Unattended -and -not $DryRun) { $go = Read-Host ' Ready? [y/N]' if ($go -notmatch "^[Yy]") { Write-Host " Nothing was changed."; exit 0 } } Invoke-Step -Number 1 -Do 'Reason 16 is a bad credential. Check the account is not locked or expired before assuming a policy fault.' -Command { Get-ADUser jbloggs -Properties LockedOut,PasswordExpired,Enabled,msNPAllowDialin | Format-List } Invoke-Step -Number 2 -Do 'msNPAllowDialin set to False overrides everything else and is easy to miss.' -Why 'The dial-in property on the user object takes precedence over the network policy. A single user failing while everyone else works is nearly always this.' -Command { Get-ADUser -Filter { msNPAllowDialin -eq $false } | Format-Table Name,SamAccountName } Invoke-Step -Number 3 -Do 'Reason 23 is a protocol mismatch. Compare what the policy permits against what the client offers.' -Command { Get-NpsNetworkPolicy | Format-List PolicyName,ProcessingOrder } Invoke-Step -Number 4 -Do 'MS-CHAPv2 requires the account''s password to be stored in a reversibly-compatible form for some methods -- check the policy is not requiring something the directory cannot supply.' -Manual Invoke-Step -Number 5 -Do 'For a machine-authenticating 802.1X deployment, confirm the computer account is being used rather than the user, and that the client is configured for computer authentication.' -Manual Write-Rule " Confirm it worked" Show-Prose 'The account authenticates and event 6272 is logged.' 'White' Write-Rule if ($script:Failed -gt 0) { Write-Host (" Finished with " + $script:Failed + " failed step(s).") -ForegroundColor Yellow Show-Prose 'Read the full write-up at https://jbtecwiz.com/support/srv-app-nps-radius' 'Yellow' } else { Write-Host ' Finished.' -ForegroundColor Green } Write-Host '' Show-Prose 'To undo: Directory attribute changes should be recorded before altering them.' 'DarkGray' Write-Rule