Network Policy Server Event ID 4421 - How To Enable RequireMsgAuth and limitProxyState?

Sonny B 141 Reputation points
2025-03-19T15:59:28.0366667+00:00

Hi Support,

We got this Envent ID 4421 warning: RequireMsgAuth and/or limitProxyState configuration is in Disable mode. These settings should be configured in Enable mode for security purposes. See https://support.microsoft.com/help/5040268 to learn more."Screen Shot 2025-03-19 at 8.43.13 AM

So we tried the steps posted on this link:

https://support.microsoft.com/en-us/topic/kb5040268-how-to-manage-the-access-request-packets-attack-vulnerability-associated-with-cve-2024-3596-a0e2f0b1-f200-4a7b-844f-48d1d5ab9e66

We tried adding the two configurations via registry editor from here:
https://learn.microsoft.com/en-us/answers/questions/2188614/enable-requiremsgauth-and-or-limitproxystate

Event logs still show this error when we restart the NPS services.

The following steps below says to open the Radius Server in the Radius Server Groups.Screen Shot 2025-03-19 at 8.50.10 AM

This section for us is blank.

Screen Shot 2025-03-19 at 8.50.55 AM

The Radius Client section is configured.

Screen Shot 2025-03-19 at 8.49.58 AM

I'm sure we're missing some configuration. Most likely the Radius Server Group?

How do we enable RequireMsgAuth and limitProxyState within the NPS GUI since it looks like the registry route didn't resolve this issue?

Any assistance is greatly appreciated.

Thank you very much,

Sonny

Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Anonymous
    2025-03-20T06:26:01.3633333+00:00

    Hello,

    Thank you for posting in Q&A forum.

    According to the official documentation provided by Microsoft, you can use the netsh command prompt to configure RequireMsgAuth and limitProxyState. I suggest you complete all the configurations and see if the relevant error message still appears.

    User's image

    https://support.microsoft.com/en-us/topic/kb5040268-how-to-manage-the-access-request-packets-attack-vulnerability-associated-with-cve-2024-3596-a0e2f0b1-f200-4a7b-844f-48d1d5ab9e66#bkmk_configurations

    I hope the information above is helpful.

    Best regards

    Zunhui

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.


  2. Sonny B 141 Reputation points
    2025-05-19T17:44:26.3466667+00:00

    Thank you very much Cole.

    Not sure if this is the right solution; however, we went into NPS and disabled the RequireMsgAuth to resolve this issue. Since we're using Duo as a 2FA for the Radius server's VPN connection.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.