{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-194-register-the-radius-speaking-access-device-not-the-end-user-computer/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-194-register-the-radius-speaking-access-device-not-the-end-user-computer/",
        "slug": "dse-20260908-194-register-the-radius-speaking-access-device-not-the-end-user-computer",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-194-register-the-radius-speaking-access-device-not-the-end-user-computer/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-194-register-the-radius-speaking-access-device-not-the-end-user-computer.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-194-register-the-radius-speaking-access-device-not-the-end-user-computer/"
        },
        "title": "Register the RADIUS-speaking access device, not the end-user computer",
        "summary": "Which system is the RADIUS client that NPS should be configured to receive requests from?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:13:57+00:00",
        "modified_at": "2026-09-08T18:26:32+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 1,
        "word_count": 192,
        "potentially_affected": "Administrators identifying RADIUS clients for Network Policy Server.",
        "dse_recommendation": "Create an inventory of the message-sending devices and the NPS servers that should receive from them.",
        "primary_source": {
            "name": "RADIUS Clients",
            "url": "https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-radius-clients",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft defines a network access server using RADIUS as a RADIUS client: it sends connection requests and accounting messages to the server. An NPS configured as a forwarding proxy is also a RADIUS client of the downstream server. Adding a RADIUS client to NPS configures it to receive Access-Request messages from that access server or proxy. <a href=\"https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-radius-clients\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft documentation</a>.</p>\n<h2>Applicability</h2>\n<p>Trace one connection request from the user’s device through the access infrastructure to NPS. Identify whether a wireless access point, VPN server, switch, or proxy actually sends the RADIUS message.</p>\n<h2>DSE recommendation</h2>\n<p>Create an inventory of the message-sending devices and the NPS servers that should receive from them. Have network-access and authentication owners review the source addresses and device identities. Document proxy hops separately and handle any shared authentication material through the approved protected process.</p>\n<h2>Verification</h2>\n<p>Generate a controlled connection attempt and correlate the sending device with the NPS request record. Confirm that the configured client represents that device or proxy and test an unapproved sender in an authorized environment. Resolve an identity or address mismatch before accepting the client registration.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-radius-clients\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: RADIUS Clients</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nMicrosoft defines a network access server using RADIUS as a RADIUS client: it sends connection requests and accounting messages to the server. An NPS configured as a forwarding proxy is also a RADIUS client of the downstream server. Adding a RADIUS client to NPS configures it to receive Access-Request messages from that access server or proxy. Microsoft documentation.\nApplicability\nTrace one connection request from the user’s device through the access infrastructure to NPS. Identify whether a wireless access point, VPN server, switch, or proxy actually sends the RADIUS message.\nDSE recommendation\nCreate an inventory of the message-sending devices and the NPS servers that should receive from them. Have network-access and authentication owners review the source addresses and device identities. Document proxy hops separately and handle any shared authentication material through the approved protected process.\nVerification\nGenerate a controlled connection attempt and correlate the sending device with the NPS request record. Confirm that the configured client represents that device or proxy and test an unapproved sender in an authorized environment. Resolve an identity or address mismatch before accepting the client registration.\nOfficial references\nMicrosoft Learn: RADIUS Clients. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft defines a network access server using RADIUS as a RADIUS client: it sends connection requests and accounting messages to the server. An NPS configured as a forwarding proxy is also a RADIUS client of the downstream server. Adding a RADIUS client to NPS configures it to receive Access-Request messages from that access server or proxy. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-radius-clients).\n\n## Applicability\n\nTrace one connection request from the user’s device through the access infrastructure to NPS. Identify whether a wireless access point, VPN server, switch, or proxy actually sends the RADIUS message.\n\n## DSE recommendation\n\nCreate an inventory of the message-sending devices and the NPS servers that should receive from them. Have network-access and authentication owners review the source addresses and device identities. Document proxy hops separately and handle any shared authentication material through the approved protected process.\n\n## Verification\n\nGenerate a controlled connection attempt and correlate the sending device with the NPS request record. Confirm that the configured client represents that device or proxy and test an unapproved sender in an authorized environment. Resolve an identity or address mismatch before accepting the client registration.\n\n## Official references\n\n[Microsoft Learn: RADIUS Clients](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-radius-clients). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-194-register-the-radius-speaking-access-device-not-the-end-user-computer/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-194-register-the-radius-speaking-access-device-not-the-end-user-computer/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-194-register-the-radius-speaking-access-device-not-the-end-user-computer/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Register the RADIUS-speaking access device, not the end-user computer",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-194-register-the-radius-speaking-access-device-not-the-end-user-computer/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-194-register-the-radius-speaking-access-device-not-the-end-user-computer/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-194-register-the-radius-speaking-access-device-not-the-end-user-computer/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-194-register-the-radius-speaking-access-device-not-the-end-user-computer/",
                "headline": "Register the RADIUS-speaking access device, not the end-user computer",
                "description": "Which system is the RADIUS client that NPS should be configured to receive requests from?",
                "abstract": "Which system is the RADIUS client that NPS should be configured to receive requests from?",
                "articleBody": "Source facts\nMicrosoft defines a network access server using RADIUS as a RADIUS client: it sends connection requests and accounting messages to the server. An NPS configured as a forwarding proxy is also a RADIUS client of the downstream server. Adding a RADIUS client to NPS configures it to receive Access-Request messages from that access server or proxy. Microsoft documentation.\nApplicability\nTrace one connection request from the user’s device through the access infrastructure to NPS. Identify whether a wireless access point, VPN server, switch, or proxy actually sends the RADIUS message.\nDSE recommendation\nCreate an inventory of the message-sending devices and the NPS servers that should receive from them. Have network-access and authentication owners review the source addresses and device identities. Document proxy hops separately and handle any shared authentication material through the approved protected process.\nVerification\nGenerate a controlled connection attempt and correlate the sending device with the NPS request record. Confirm that the configured client represents that device or proxy and test an unapproved sender in an authorized environment. Resolve an identity or address mismatch before accepting the client registration.\nOfficial references\nMicrosoft Learn: RADIUS Clients. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:13:57+00:00",
                "dateModified": "2026-09-08T18:26:32+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-194-register-the-radius-speaking-access-device-not-the-end-user-computer/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-194-register-the-radius-speaking-access-device-not-the-end-user-computer/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Register the RADIUS-speaking access device, not the end-user computer"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 192,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "RADIUS Clients",
                    "url": "https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-radius-clients"
                }
            }
        ]
    }
}