{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-212-protect-an-nps-configuration-export-and-review-its-import-limits/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-212-protect-an-nps-configuration-export-and-review-its-import-limits/",
        "slug": "dse-20260908-212-protect-an-nps-configuration-export-and-review-its-import-limits",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-212-protect-an-nps-configuration-export-and-review-its-import-limits/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-212-protect-an-nps-configuration-export-and-review-its-import-limits.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-212-protect-an-nps-configuration-export-and-review-its-import-limits/"
        },
        "title": "Protect an NPS configuration export and review its import limits",
        "summary": "What must be reviewed before importing an exported NPS configuration?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:13:39+00:00",
        "modified_at": "2026-09-08T18:29:33+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 2,
        "word_count": 234,
        "potentially_affected": "Administrators moving Network Policy Server settings between Windows servers.",
        "dse_recommendation": "Store the export in an access-controlled location and name the administrators authorized to handle it.",
        "primary_source": {
            "name": "Export an NPS Configuration for Import on Another Server",
            "url": "https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-manage-export",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Importing an NPS configuration replaces the destination settings rather than merging with them. Microsoft prohibits this procedure when the source NPS database version is newer than the destination database. SQL Server logging settings are excluded from the export and must be configured manually on the receiving NPS. A Netsh export contains unencrypted RADIUS shared secrets in its XML file. <a href=\"https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-manage-export\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the source and destination roles and verify the supported export and import method for their server versions. Review the complete configuration scope before treating the file as a single-policy backup. Account for server-specific endpoints and logging destinations in the transfer plan.</p>\n<h2>DSE recommendation</h2>\n<p>Store the export in an access-controlled location and name the administrators authorized to handle it. Record the source configuration and capture the destination&#8217;s current settings before import. Have the receiving owner review clients, remote servers, policy order, and logging configuration for that environment. Use a nonproduction transfer exercise before replacing settings on an active authentication server.</p>\n<h2>Verification</h2>\n<p>Refresh the management view and compare the imported settings with the approved transfer inventory. Test representative local and forwarded requests, accounting where applicable, and a request that should be rejected. Record the configuration differences and functional results separately. Remove temporary transfer access according to the approved handling plan once the import is accepted.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-manage-export\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Export an NPS Configuration for Import on Another Server</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nImporting an NPS configuration replaces the destination settings rather than merging with them. Microsoft prohibits this procedure when the source NPS database version is newer than the destination database. SQL Server logging settings are excluded from the export and must be configured manually on the receiving NPS. A Netsh export contains unencrypted RADIUS shared secrets in its XML file. Microsoft Learn.\nApplicability\nIdentify the source and destination roles and verify the supported export and import method for their server versions. Review the complete configuration scope before treating the file as a single-policy backup. Account for server-specific endpoints and logging destinations in the transfer plan.\nDSE recommendation\nStore the export in an access-controlled location and name the administrators authorized to handle it. Record the source configuration and capture the destination’s current settings before import. Have the receiving owner review clients, remote servers, policy order, and logging configuration for that environment. Use a nonproduction transfer exercise before replacing settings on an active authentication server.\nVerification\nRefresh the management view and compare the imported settings with the approved transfer inventory. Test representative local and forwarded requests, accounting where applicable, and a request that should be rejected. Record the configuration differences and functional results separately. Remove temporary transfer access according to the approved handling plan once the import is accepted.\nOfficial references\nMicrosoft Learn: Export an NPS Configuration for Import on Another Server. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nImporting an NPS configuration replaces the destination settings rather than merging with them. Microsoft prohibits this procedure when the source NPS database version is newer than the destination database. SQL Server logging settings are excluded from the export and must be configured manually on the receiving NPS. A Netsh export contains unencrypted RADIUS shared secrets in its XML file. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-manage-export).\n\n## Applicability\n\nIdentify the source and destination roles and verify the supported export and import method for their server versions. Review the complete configuration scope before treating the file as a single-policy backup. Account for server-specific endpoints and logging destinations in the transfer plan.\n\n## DSE recommendation\n\nStore the export in an access-controlled location and name the administrators authorized to handle it. Record the source configuration and capture the destination’s current settings before import. Have the receiving owner review clients, remote servers, policy order, and logging configuration for that environment. Use a nonproduction transfer exercise before replacing settings on an active authentication server.\n\n## Verification\n\nRefresh the management view and compare the imported settings with the approved transfer inventory. Test representative local and forwarded requests, accounting where applicable, and a request that should be rejected. Record the configuration differences and functional results separately. Remove temporary transfer access according to the approved handling plan once the import is accepted.\n\n## Official references\n\n[Microsoft Learn: Export an NPS Configuration for Import on Another Server](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-manage-export). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-212-protect-an-nps-configuration-export-and-review-its-import-limits/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-212-protect-an-nps-configuration-export-and-review-its-import-limits/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-212-protect-an-nps-configuration-export-and-review-its-import-limits/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Protect an NPS configuration export and review its import limits",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-212-protect-an-nps-configuration-export-and-review-its-import-limits/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-212-protect-an-nps-configuration-export-and-review-its-import-limits/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-212-protect-an-nps-configuration-export-and-review-its-import-limits/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-212-protect-an-nps-configuration-export-and-review-its-import-limits/",
                "headline": "Protect an NPS configuration export and review its import limits",
                "description": "What must be reviewed before importing an exported NPS configuration?",
                "abstract": "What must be reviewed before importing an exported NPS configuration?",
                "articleBody": "Source facts\nImporting an NPS configuration replaces the destination settings rather than merging with them. Microsoft prohibits this procedure when the source NPS database version is newer than the destination database. SQL Server logging settings are excluded from the export and must be configured manually on the receiving NPS. A Netsh export contains unencrypted RADIUS shared secrets in its XML file. Microsoft Learn.\nApplicability\nIdentify the source and destination roles and verify the supported export and import method for their server versions. Review the complete configuration scope before treating the file as a single-policy backup. Account for server-specific endpoints and logging destinations in the transfer plan.\nDSE recommendation\nStore the export in an access-controlled location and name the administrators authorized to handle it. Record the source configuration and capture the destination’s current settings before import. Have the receiving owner review clients, remote servers, policy order, and logging configuration for that environment. Use a nonproduction transfer exercise before replacing settings on an active authentication server.\nVerification\nRefresh the management view and compare the imported settings with the approved transfer inventory. Test representative local and forwarded requests, accounting where applicable, and a request that should be rejected. Record the configuration differences and functional results separately. Remove temporary transfer access according to the approved handling plan once the import is accepted.\nOfficial references\nMicrosoft Learn: Export an NPS Configuration for Import on Another Server. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:13:39+00:00",
                "dateModified": "2026-09-08T18:29:33+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-212-protect-an-nps-configuration-export-and-review-its-import-limits/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-212-protect-an-nps-configuration-export-and-review-its-import-limits/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Protect an NPS configuration export and review its import limits"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 234,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Export an NPS Configuration for Import on Another Server",
                    "url": "https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-manage-export"
                }
            }
        ]
    }
}