Intermittent Wi-Fi RADIUS failures

Scott Lee 0 Reputation points
2026-09-17T16:08:52.7033333+00:00

Hello guys

Our wireless access point AP-04 is intermittently dropping WPA2-Enterprise authentication requests, and I’m not sure whether the issue is coming from the AP or the RADIUS server.

How can we check the RADIUS server logs to confirm whether the authentication requests are reaching the server and identify why some requests are being rejected or timing out ?

Thanks

Windows for business | Windows 365 Enterprise
0 comments No comments

3 answers

Sort by: Most helpful
  1. HLBui 13,020 Reputation points Independent Advisor
    2026-09-21T07:22:26.6666667+00:00

    If everything is okay, don't forget to share your experience with the issue by "Accept answer". If you need more information, feel free to leave a message. We are happy to help!

    Was this answer helpful?

    0 comments No comments

  2. HLBui 13,020 Reputation points Independent Advisor
    2026-09-17T16:58:11.5533333+00:00

    Hi Scott Lee •

    Please , start by checking the RADIUS server logs at the exact time AP-04 reports an authentication failure. If you’re using Windows NPS, open Event Viewer > Custom Views > Server Roles > Network Policy and Access Services and look for the corresponding authentication events. The logs can usually show whether the request reached NPS, which policy was evaluated, and whether it was accepted, rejected, or failed because of a timeout or client configuration issue.

    On the RADIUS server, also verify that AP-04 is configured with the correct IP address and shared secret, since a mismatch can cause authentication requests to fail. If no event appears when a user tries to connect, I’d focus on the network path or AP-04 rather than the RADIUS policy itself. You can also compare successful and failed attempts by checking timestamps, client usernames, and authentication methods to spot a pattern.

    If this helps resolve the issue, please click “Accept Answer” so others in the community can find the solution more easily.

    Was this answer helpful?

    0 comments No comments

  3. AI answer

    2026-09-17T16:09:21.87+00:00

    Use both the NPS-side logs and the client/AP-side traces to determine whether requests from AP-04 are reaching the RADIUS server and where they fail.

    1. Confirm AP-04 is configured as a RADIUS client in NPS. In NPS, wireless access points are treated as RADIUS clients. If AP-04 is not configured correctly as a RADIUS client, NPS will not process its authentication requests as expected.
    2. Check the NPS policy and EAP configuration. In NPS snap-in go to Policies > Network Policies > right-click the relevant policy > Properties > Constraints > Authentication Methods. This shows which EAP method and server certificate are being used. This is important because many 802.1X failures are caused by certificate problems such as invalid, expired, chain verification, or revocation failures.
    3. Review client-side 802.1X operational logs. For wireless clients, open Event Viewer (Local)\Applications and Services Logs\Microsoft\Windows\WLAN-AutoConfig/Operational. For wired scenarios, the equivalent is Wired-AutoConfig/Operational. These logs show the wireless adapter, wireless profile properties, authentication method, and the reason for failure. If requests are timing out, these logs help show whether the failure happened before or during 802.1X authentication.
    4. Enable CAPI2 logging for certificate-related failures. In Event Viewer (Local)\Applications and Services Logs\Microsoft\Windows\CAPI2, enable Operational. This is useful when EAP uses certificates and helps identify certificate trust, chain, expiration, or revocation problems.
    5. Collect an NPS trace and client trace during a failed attempt. Create C:\MSLOG on both the client and the NPS server, then run these commands from an elevated command prompt. On the wireless client:
         netsh ras set tracing * enabled
         netsh trace start scenario=wlan,wlan_wpp,wlan_dbg,wireless_dbg globallevel=0xff capture=yes maxsize=1024 tracefile=C:\MSLOG\%COMPUTERNAME%_wireless_cli.etl
      
      On the NPS server:
         netsh ras set tracing * enabled
         netsh trace start scenario=wlan,wlan_wpp,wlan_dbg,wireless_dbg globallevel=0xff capture=yes maxsize=1024 tracefile=C:\MSLOG\%COMPUTERNAME%_wireless_nps.etl
      
      Also enable CAPI2 logging:
         wevtutil.exe sl Microsoft-Windows-CAPI2/Operational /e:true
         wevtutil sl Microsoft-Windows-CAPI2/Operational /ms:104857600
      
      These traces help confirm whether the authentication exchange reached NPS and whether certificate or EAP processing failed.
    6. Check whether the issue is specific to AP-04. Determine whether all clients are affected or only clients using that AP. If only AP-04 users are affected, compare with other APs and check for common factors. Also verify whether the SSID is hidden and whether the wireless profile is deployed consistently.
    7. If the server appears to ignore some requests and clients time out, check for a RADIUS state attribute issue. A documented cause of long authentication delays is when a wireless access point sends a RADIUS state attribute in the initial EAP authentication request. In that case, IAS/NPS can ignore the request, and the client waits until timeout. On the server, this can appear in the IAS log as: State attribute is present, but unrecognized The IAS log file is Iaslog.log under %WINDIR%\System32\LogFiles.
    8. Correlate AP behavior with the server result. If the NPS trace and logs show no request arriving during a failed attempt, the issue is likely on AP-04 or between AP-04 and the RADIUS server. If the request arrives and fails, the NPS policy, EAP method, or certificate validation is the next place to focus.

    A practical end-to-end check is:

    • Start NPS trace and CAPI2 logging.
    • Reproduce a failure from a client connected through AP-04.
    • Check WLAN-AutoConfig/Operational on the client.
    • Check the NPS policy EAP settings.
    • Review Iaslog.log for ignored or malformed requests.
    • Compare a successful attempt from another AP against a failed AP-04 attempt.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.