Hi Manon David,
To verify the MAC address format received by Windows Server Network Policy Server, open Event Viewer via eventvwr.msc, select the Security log under Windows Logs, and filter for Event ID 6273. This audit failure event records each rejected RADIUS request and exposes the exact character string passed by the network switch within the Account Name and Calling Station Identifier fields, allowing you to confirm whether the switch transmitted the address using hyphens, colons, dotted quads, or raw contiguous characters.
If requests are not generating Event ID 6273, inspect the raw text logs under C:\Windows\System32\LogFiles to review recorded RADIUS transactions, or capture traffic directly on the server over UDP port 1812 using a packet analyzer to inspect incoming Access-Request packets off the wire. Once the format mismatch is identified, you can either adjust the switch configuration to match your Active Directory account naming convention or configure an Attribute Manipulation rule within an NPS Connection Request Policy to strip delimiters and normalize the incoming MAC string before evaluation.
Hope this answer has brought you some useful information. If it did, please hit “accept answer”. Should you have any questions, feel free to leave a comment.
VPHAN