{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-140-check-that-nps-can-select-an-auto-enrolled-server-certificate/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-140-check-that-nps-can-select-an-auto-enrolled-server-certificate/",
        "slug": "dse-20260908-140-check-that-nps-can-select-an-auto-enrolled-server-certificate",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-140-check-that-nps-can-select-an-auto-enrolled-server-certificate/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-140-check-that-nps-can-select-an-auto-enrolled-server-certificate.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-140-check-that-nps-can-select-an-auto-enrolled-server-certificate/"
        },
        "title": "Check that NPS can select an auto-enrolled server certificate",
        "summary": "How can an NPS administrator verify an enrolled certificate without leaving a test policy behind?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:14:51+00:00",
        "modified_at": "2026-09-08T18:23:27+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 1,
        "word_count": 198,
        "potentially_affected": "Administrators checking NPS server certificates after configuring certificate auto-enrollment.",
        "dse_recommendation": "Record the expected certificate identity and have the PKI and authentication owners review it together.",
        "primary_source": {
            "name": "Configure Certificate Auto-Enrollment for Network Policy Server",
            "url": "https://learn.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/server-certs/configure-server-certificate-auto-enrollment",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft’s NPS auto-enrollment procedure uses Group Policy to manage certificate issuance and renewal in an Active Directory environment. After refreshing policy, its verification procedure begins a test network-policy workflow so NPS can confirm that the enrolled certificate is usable for authentication. The administrator does not finish that wizard. Consequently, the certificate can be checked without creating the test network policy. <a href=\"https://learn.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/server-certs/configure-server-certificate-auto-enrollment\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft documentation</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the NPS server, certificate template, policy scope, issuing authority, and intended authentication method. Review the source’s enrollment prerequisites and confirm that the certificate being inspected belongs to the intended server.</p>\n<h2>DSE recommendation</h2>\n<p>Record the expected certificate identity and have the PKI and authentication owners review it together. Follow the documented inspection workflow, noting where the wizard must be cancelled. Keep certificate inspection separate from approval of any new access policy.</p>\n<h2>Verification</h2>\n<p>Confirm that the expected certificate is offered and accepted in the relevant NPS authentication configuration. Cancel the temporary workflow and verify that no unintended policy was left behind. Then conduct the approved authentication test and preserve the certificate identity and result without recording private-key material.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/server-certs/configure-server-certificate-auto-enrollment\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Configure Certificate Auto-Enrollment for Network Policy Server</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nMicrosoft’s NPS auto-enrollment procedure uses Group Policy to manage certificate issuance and renewal in an Active Directory environment. After refreshing policy, its verification procedure begins a test network-policy workflow so NPS can confirm that the enrolled certificate is usable for authentication. The administrator does not finish that wizard. Consequently, the certificate can be checked without creating the test network policy. Microsoft documentation.\nApplicability\nIdentify the NPS server, certificate template, policy scope, issuing authority, and intended authentication method. Review the source’s enrollment prerequisites and confirm that the certificate being inspected belongs to the intended server.\nDSE recommendation\nRecord the expected certificate identity and have the PKI and authentication owners review it together. Follow the documented inspection workflow, noting where the wizard must be cancelled. Keep certificate inspection separate from approval of any new access policy.\nVerification\nConfirm that the expected certificate is offered and accepted in the relevant NPS authentication configuration. Cancel the temporary workflow and verify that no unintended policy was left behind. Then conduct the approved authentication test and preserve the certificate identity and result without recording private-key material.\nOfficial references\nMicrosoft Learn: Configure Certificate Auto-Enrollment for Network Policy Server. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft’s NPS auto-enrollment procedure uses Group Policy to manage certificate issuance and renewal in an Active Directory environment. After refreshing policy, its verification procedure begins a test network-policy workflow so NPS can confirm that the enrolled certificate is usable for authentication. The administrator does not finish that wizard. Consequently, the certificate can be checked without creating the test network policy. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/server-certs/configure-server-certificate-auto-enrollment).\n\n## Applicability\n\nIdentify the NPS server, certificate template, policy scope, issuing authority, and intended authentication method. Review the source’s enrollment prerequisites and confirm that the certificate being inspected belongs to the intended server.\n\n## DSE recommendation\n\nRecord the expected certificate identity and have the PKI and authentication owners review it together. Follow the documented inspection workflow, noting where the wizard must be cancelled. Keep certificate inspection separate from approval of any new access policy.\n\n## Verification\n\nConfirm that the expected certificate is offered and accepted in the relevant NPS authentication configuration. Cancel the temporary workflow and verify that no unintended policy was left behind. Then conduct the approved authentication test and preserve the certificate identity and result without recording private-key material.\n\n## Official references\n\n[Microsoft Learn: Configure Certificate Auto-Enrollment for Network Policy Server](https://learn.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/server-certs/configure-server-certificate-auto-enrollment). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-140-check-that-nps-can-select-an-auto-enrolled-server-certificate/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-140-check-that-nps-can-select-an-auto-enrolled-server-certificate/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-140-check-that-nps-can-select-an-auto-enrolled-server-certificate/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Check that NPS can select an auto-enrolled server certificate",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-140-check-that-nps-can-select-an-auto-enrolled-server-certificate/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-140-check-that-nps-can-select-an-auto-enrolled-server-certificate/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-140-check-that-nps-can-select-an-auto-enrolled-server-certificate/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-140-check-that-nps-can-select-an-auto-enrolled-server-certificate/",
                "headline": "Check that NPS can select an auto-enrolled server certificate",
                "description": "How can an NPS administrator verify an enrolled certificate without leaving a test policy behind?",
                "abstract": "How can an NPS administrator verify an enrolled certificate without leaving a test policy behind?",
                "articleBody": "Source facts\nMicrosoft’s NPS auto-enrollment procedure uses Group Policy to manage certificate issuance and renewal in an Active Directory environment. After refreshing policy, its verification procedure begins a test network-policy workflow so NPS can confirm that the enrolled certificate is usable for authentication. The administrator does not finish that wizard. Consequently, the certificate can be checked without creating the test network policy. Microsoft documentation.\nApplicability\nIdentify the NPS server, certificate template, policy scope, issuing authority, and intended authentication method. Review the source’s enrollment prerequisites and confirm that the certificate being inspected belongs to the intended server.\nDSE recommendation\nRecord the expected certificate identity and have the PKI and authentication owners review it together. Follow the documented inspection workflow, noting where the wizard must be cancelled. Keep certificate inspection separate from approval of any new access policy.\nVerification\nConfirm that the expected certificate is offered and accepted in the relevant NPS authentication configuration. Cancel the temporary workflow and verify that no unintended policy was left behind. Then conduct the approved authentication test and preserve the certificate identity and result without recording private-key material.\nOfficial references\nMicrosoft Learn: Configure Certificate Auto-Enrollment for Network Policy Server. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:14:51+00:00",
                "dateModified": "2026-09-08T18:23:27+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-140-check-that-nps-can-select-an-auto-enrolled-server-certificate/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-140-check-that-nps-can-select-an-auto-enrolled-server-certificate/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Check that NPS can select an auto-enrolled server certificate"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 198,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure Certificate Auto-Enrollment for Network Policy Server",
                    "url": "https://learn.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/server-certs/configure-server-certificate-auto-enrollment"
                }
            }
        ]
    }
}