{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-063-plan-nps-server-certificates-even-when-wi-fi-users-authenticate-with-passwords/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-063-plan-nps-server-certificates-even-when-wi-fi-users-authenticate-with-passwords/",
        "slug": "dse-20260908-063-plan-nps-server-certificates-even-when-wi-fi-users-authenticate-with-passwords",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-063-plan-nps-server-certificates-even-when-wi-fi-users-authenticate-with-passwords/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-063-plan-nps-server-certificates-even-when-wi-fi-users-authenticate-with-passwords.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-063-plan-nps-server-certificates-even-when-wi-fi-users-authenticate-with-passwords/"
        },
        "title": "Plan NPS server certificates even when Wi-Fi users authenticate with passwords",
        "summary": "Why does the password-based 802.1X wireless design still require NPS certificates?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:16:08+00:00",
        "modified_at": "2026-09-08T18:20:22+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 1,
        "word_count": 202,
        "potentially_affected": "Use this review for the documented password-based wireless design and supported client population.",
        "dse_recommendation": "Keep the user credential decision separate from the authentication-server certificate plan.",
        "primary_source": {
            "name": "Deploy Password-Based 802.1X Authenticated Wireless Access",
            "url": "https://learn.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/wireless/a-deploy-8021X-wireless-access",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>The documented PEAP-MS-CHAP v2 design uses password credentials for user authentication. That same deployment guide still requires server certificates on the authenticating NPS servers. Microsoft identifies an internal AD CS deployment or a public certification authority as options for issuing those server certificates. <a href=\"https://learn.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/wireless/a-deploy-8021X-wireless-access\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft documentation</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review for the documented password-based wireless design and supported client population. Identify every authenticating NPS server, its certificate source, and the client trust configuration. Review current authentication guidance before selecting this method.</p>\n<h2>DSE recommendation</h2>\n<p>Keep the user credential decision separate from the authentication-server certificate plan. Have the wireless, identity, and certificate owners review the expected server identities and trust anchors together. Record who will renew each NPS certificate and how a replacement will be tested. Include a deliberately untrusted server identity in the approved client-validation test plan.</p>\n<h2>Verification</h2>\n<p>Test a representative client against the intended NPS service and inspect the server certificate involved. Verify the approved behavior when server identity or trust does not match the client configuration. Preserve the connection result and certificate identity without capturing user passwords. Resolve a validation or renewal gap before expanding wireless enrollment.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/wireless/a-deploy-8021X-wireless-access\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Deploy Password-Based 802.1X Authenticated Wireless Access</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nThe documented PEAP-MS-CHAP v2 design uses password credentials for user authentication. That same deployment guide still requires server certificates on the authenticating NPS servers. Microsoft identifies an internal AD CS deployment or a public certification authority as options for issuing those server certificates. Microsoft documentation.\nApplicability\nUse this review for the documented password-based wireless design and supported client population. Identify every authenticating NPS server, its certificate source, and the client trust configuration. Review current authentication guidance before selecting this method.\nDSE recommendation\nKeep the user credential decision separate from the authentication-server certificate plan. Have the wireless, identity, and certificate owners review the expected server identities and trust anchors together. Record who will renew each NPS certificate and how a replacement will be tested. Include a deliberately untrusted server identity in the approved client-validation test plan.\nVerification\nTest a representative client against the intended NPS service and inspect the server certificate involved. Verify the approved behavior when server identity or trust does not match the client configuration. Preserve the connection result and certificate identity without capturing user passwords. Resolve a validation or renewal gap before expanding wireless enrollment.\nOfficial references\nMicrosoft Learn: Deploy Password-Based 802.1X Authenticated Wireless Access. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nThe documented PEAP-MS-CHAP v2 design uses password credentials for user authentication. That same deployment guide still requires server certificates on the authenticating NPS servers. Microsoft identifies an internal AD CS deployment or a public certification authority as options for issuing those server certificates. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/wireless/a-deploy-8021X-wireless-access).\n\n## Applicability\n\nUse this review for the documented password-based wireless design and supported client population. Identify every authenticating NPS server, its certificate source, and the client trust configuration. Review current authentication guidance before selecting this method.\n\n## DSE recommendation\n\nKeep the user credential decision separate from the authentication-server certificate plan. Have the wireless, identity, and certificate owners review the expected server identities and trust anchors together. Record who will renew each NPS certificate and how a replacement will be tested. Include a deliberately untrusted server identity in the approved client-validation test plan.\n\n## Verification\n\nTest a representative client against the intended NPS service and inspect the server certificate involved. Verify the approved behavior when server identity or trust does not match the client configuration. Preserve the connection result and certificate identity without capturing user passwords. Resolve a validation or renewal gap before expanding wireless enrollment.\n\n## Official references\n\n[Microsoft Learn: Deploy Password-Based 802.1X Authenticated Wireless Access](https://learn.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/wireless/a-deploy-8021X-wireless-access). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-063-plan-nps-server-certificates-even-when-wi-fi-users-authenticate-with-passwords/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-063-plan-nps-server-certificates-even-when-wi-fi-users-authenticate-with-passwords/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-063-plan-nps-server-certificates-even-when-wi-fi-users-authenticate-with-passwords/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Plan NPS server certificates even when Wi-Fi users authenticate with passwords",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-063-plan-nps-server-certificates-even-when-wi-fi-users-authenticate-with-passwords/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-063-plan-nps-server-certificates-even-when-wi-fi-users-authenticate-with-passwords/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-063-plan-nps-server-certificates-even-when-wi-fi-users-authenticate-with-passwords/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-063-plan-nps-server-certificates-even-when-wi-fi-users-authenticate-with-passwords/",
                "headline": "Plan NPS server certificates even when Wi-Fi users authenticate with passwords",
                "description": "Why does the password-based 802.1X wireless design still require NPS certificates?",
                "abstract": "Why does the password-based 802.1X wireless design still require NPS certificates?",
                "articleBody": "Source facts\nThe documented PEAP-MS-CHAP v2 design uses password credentials for user authentication. That same deployment guide still requires server certificates on the authenticating NPS servers. Microsoft identifies an internal AD CS deployment or a public certification authority as options for issuing those server certificates. Microsoft documentation.\nApplicability\nUse this review for the documented password-based wireless design and supported client population. Identify every authenticating NPS server, its certificate source, and the client trust configuration. Review current authentication guidance before selecting this method.\nDSE recommendation\nKeep the user credential decision separate from the authentication-server certificate plan. Have the wireless, identity, and certificate owners review the expected server identities and trust anchors together. Record who will renew each NPS certificate and how a replacement will be tested. Include a deliberately untrusted server identity in the approved client-validation test plan.\nVerification\nTest a representative client against the intended NPS service and inspect the server certificate involved. Verify the approved behavior when server identity or trust does not match the client configuration. Preserve the connection result and certificate identity without capturing user passwords. Resolve a validation or renewal gap before expanding wireless enrollment.\nOfficial references\nMicrosoft Learn: Deploy Password-Based 802.1X Authenticated Wireless Access. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:16:08+00:00",
                "dateModified": "2026-09-08T18:20:22+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-063-plan-nps-server-certificates-even-when-wi-fi-users-authenticate-with-passwords/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-063-plan-nps-server-certificates-even-when-wi-fi-users-authenticate-with-passwords/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Plan NPS server certificates even when Wi-Fi users authenticate with passwords"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 202,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Deploy Password-Based 802.1X Authenticated Wireless Access",
                    "url": "https://learn.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/wireless/a-deploy-8021X-wireless-access"
                }
            }
        ]
    }
}