{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-200-review-nps-authorization-as-an-ordered-network-policy-decision/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-200-review-nps-authorization-as-an-ordered-network-policy-decision/",
        "slug": "dse-20260908-200-review-nps-authorization-as-an-ordered-network-policy-decision",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-200-review-nps-authorization-as-an-ordered-network-policy-decision/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-200-review-nps-authorization-as-an-ordered-network-policy-decision.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-200-review-nps-authorization-as-an-ordered-network-policy-decision/"
        },
        "title": "Review NPS authorization as an ordered network-policy decision",
        "summary": "Which network policy and account setting determine an NPS authorization result?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:13:51+00:00",
        "modified_at": "2026-09-08T18:26:32+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 1,
        "word_count": 214,
        "potentially_affected": "Administrators reviewing connection authorization on a Network Policy Server.",
        "dse_recommendation": "Have the access owner state the intended result for a representative permitted account and a prohibited account.",
        "primary_source": {
            "name": "Configure Network Policies",
            "url": "https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-np-configure",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>NPS uses network policies together with account dial-in properties to decide whether a connection request is authorized. It compares a request against the ordered policy list and uses a matching policy with the user account properties for authorization. When that evaluation authorizes the connection, NPS applies the matching network policy settings. <a href=\"https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-np-configure\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Start with an identified request and its account, not a policy name that merely appears relevant. Distinguish authorization by a network policy from forwarding or local processing selected by a connection request policy. Preserve the ordering as part of the evidence.</p>\n<h2>DSE recommendation</h2>\n<p>Have the access owner state the intended result for a representative permitted account and a prohibited account. Compare their request characteristics with the ordered network policies and inspect the relevant dial-in settings. Before changing a condition or moving a policy, list other request populations that may match it. Keep the original policy order and account settings available for a controlled reversal.</p>\n<h2>Verification</h2>\n<p>Run the approved permitted and prohibited connection tests. Record the policy that handled each request, the account setting used in the decision, and the resulting access. If the result differs from the design, investigate earlier matching policies before broadening the intended policy conditions.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-np-configure\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Configure Network Policies</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nNPS uses network policies together with account dial-in properties to decide whether a connection request is authorized. It compares a request against the ordered policy list and uses a matching policy with the user account properties for authorization. When that evaluation authorizes the connection, NPS applies the matching network policy settings. Microsoft Learn.\nApplicability\nStart with an identified request and its account, not a policy name that merely appears relevant. Distinguish authorization by a network policy from forwarding or local processing selected by a connection request policy. Preserve the ordering as part of the evidence.\nDSE recommendation\nHave the access owner state the intended result for a representative permitted account and a prohibited account. Compare their request characteristics with the ordered network policies and inspect the relevant dial-in settings. Before changing a condition or moving a policy, list other request populations that may match it. Keep the original policy order and account settings available for a controlled reversal.\nVerification\nRun the approved permitted and prohibited connection tests. Record the policy that handled each request, the account setting used in the decision, and the resulting access. If the result differs from the design, investigate earlier matching policies before broadening the intended policy conditions.\nOfficial references\nMicrosoft Learn: Configure Network Policies. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nNPS uses network policies together with account dial-in properties to decide whether a connection request is authorized. It compares a request against the ordered policy list and uses a matching policy with the user account properties for authorization. When that evaluation authorizes the connection, NPS applies the matching network policy settings. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-np-configure).\n\n## Applicability\n\nStart with an identified request and its account, not a policy name that merely appears relevant. Distinguish authorization by a network policy from forwarding or local processing selected by a connection request policy. Preserve the ordering as part of the evidence.\n\n## DSE recommendation\n\nHave the access owner state the intended result for a representative permitted account and a prohibited account. Compare their request characteristics with the ordered network policies and inspect the relevant dial-in settings. Before changing a condition or moving a policy, list other request populations that may match it. Keep the original policy order and account settings available for a controlled reversal.\n\n## Verification\n\nRun the approved permitted and prohibited connection tests. Record the policy that handled each request, the account setting used in the decision, and the resulting access. If the result differs from the design, investigate earlier matching policies before broadening the intended policy conditions.\n\n## Official references\n\n[Microsoft Learn: Configure Network Policies](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-np-configure). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-200-review-nps-authorization-as-an-ordered-network-policy-decision/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-200-review-nps-authorization-as-an-ordered-network-policy-decision/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-200-review-nps-authorization-as-an-ordered-network-policy-decision/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Review NPS authorization as an ordered network-policy decision",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-200-review-nps-authorization-as-an-ordered-network-policy-decision/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-200-review-nps-authorization-as-an-ordered-network-policy-decision/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-200-review-nps-authorization-as-an-ordered-network-policy-decision/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-200-review-nps-authorization-as-an-ordered-network-policy-decision/",
                "headline": "Review NPS authorization as an ordered network-policy decision",
                "description": "Which network policy and account setting determine an NPS authorization result?",
                "abstract": "Which network policy and account setting determine an NPS authorization result?",
                "articleBody": "Source facts\nNPS uses network policies together with account dial-in properties to decide whether a connection request is authorized. It compares a request against the ordered policy list and uses a matching policy with the user account properties for authorization. When that evaluation authorizes the connection, NPS applies the matching network policy settings. Microsoft Learn.\nApplicability\nStart with an identified request and its account, not a policy name that merely appears relevant. Distinguish authorization by a network policy from forwarding or local processing selected by a connection request policy. Preserve the ordering as part of the evidence.\nDSE recommendation\nHave the access owner state the intended result for a representative permitted account and a prohibited account. Compare their request characteristics with the ordered network policies and inspect the relevant dial-in settings. Before changing a condition or moving a policy, list other request populations that may match it. Keep the original policy order and account settings available for a controlled reversal.\nVerification\nRun the approved permitted and prohibited connection tests. Record the policy that handled each request, the account setting used in the decision, and the resulting access. If the result differs from the design, investigate earlier matching policies before broadening the intended policy conditions.\nOfficial references\nMicrosoft Learn: Configure Network Policies. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:13:51+00:00",
                "dateModified": "2026-09-08T18:26:32+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-200-review-nps-authorization-as-an-ordered-network-policy-decision/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-200-review-nps-authorization-as-an-ordered-network-policy-decision/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Review NPS authorization as an ordered network-policy decision"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 214,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure Network Policies",
                    "url": "https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-np-configure"
                }
            }
        ]
    }
}