{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-232-check-the-subject-and-user-name-fields-in-nps-certificate-templates/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-232-check-the-subject-and-user-name-fields-in-nps-certificate-templates/",
        "slug": "dse-20260908-232-check-the-subject-and-user-name-fields-in-nps-certificate-templates",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-232-check-the-subject-and-user-name-fields-in-nps-certificate-templates/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-232-check-the-subject-and-user-name-fields-in-nps-certificate-templates.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-232-check-the-subject-and-user-name-fields-in-nps-certificate-templates/"
        },
        "title": "Check the subject and user-name fields in NPS certificate templates",
        "summary": "Which identity fields must be populated for the documented NPS server and user certificates?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:13:19+00:00",
        "modified_at": "2026-09-08T18:29:34+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 2,
        "word_count": 222,
        "potentially_affected": "Administrators preparing AD CS certificate templates for PEAP and EAP network authentication.",
        "dse_recommendation": "Have the PKI and network-access owners review the intended Subject and UPN population before enrolling pilot identities.",
        "primary_source": {
            "name": "Configure Certificate Templates for PEAP and EAP requirements",
            "url": "https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-manage-cert-requirements",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft says an NPS server certificate with a blank Subject is unavailable for NPS authentication. Its template instructions choose a Subject name format other than None and build the name from directory information. For user certificates, the documented client requirement places the user principal name in the Subject Alternative Name extension. <a href=\"https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-manage-cert-requirements\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify whether the template issues a server or user certificate and review the complete requirements for the chosen authentication method. Inspect an actual issued certificate as well as the template. Keep these identity fields separate from the certificate&#8217;s issuer, purposes, validity, and trust-chain checks.</p>\n<h2>DSE recommendation</h2>\n<p>Have the PKI and network-access owners review the intended Subject and UPN population before enrolling pilot identities. Record the template version, enrollment scope, and expected certificate fields. Use a dedicated test server or user so the resulting certificate can be inspected without changing an entire deployment. Preserve the prior template configuration and document any requested correction.</p>\n<h2>Verification</h2>\n<p>Examine the issued certificate and compare its Subject or user UPN field with the approved identity. Confirm the intended server certificate is available in NPS and exercise the selected authentication method with the pilot. Record missing fields and selection failures separately from other chain-validation errors before widening enrollment.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-manage-cert-requirements\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Configure Certificate Templates for PEAP and EAP requirements</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nMicrosoft says an NPS server certificate with a blank Subject is unavailable for NPS authentication. Its template instructions choose a Subject name format other than None and build the name from directory information. For user certificates, the documented client requirement places the user principal name in the Subject Alternative Name extension. Microsoft Learn.\nApplicability\nIdentify whether the template issues a server or user certificate and review the complete requirements for the chosen authentication method. Inspect an actual issued certificate as well as the template. Keep these identity fields separate from the certificate’s issuer, purposes, validity, and trust-chain checks.\nDSE recommendation\nHave the PKI and network-access owners review the intended Subject and UPN population before enrolling pilot identities. Record the template version, enrollment scope, and expected certificate fields. Use a dedicated test server or user so the resulting certificate can be inspected without changing an entire deployment. Preserve the prior template configuration and document any requested correction.\nVerification\nExamine the issued certificate and compare its Subject or user UPN field with the approved identity. Confirm the intended server certificate is available in NPS and exercise the selected authentication method with the pilot. Record missing fields and selection failures separately from other chain-validation errors before widening enrollment.\nOfficial references\nMicrosoft Learn: Configure Certificate Templates for PEAP and EAP requirements. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft says an NPS server certificate with a blank Subject is unavailable for NPS authentication. Its template instructions choose a Subject name format other than None and build the name from directory information. For user certificates, the documented client requirement places the user principal name in the Subject Alternative Name extension. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-manage-cert-requirements).\n\n## Applicability\n\nIdentify whether the template issues a server or user certificate and review the complete requirements for the chosen authentication method. Inspect an actual issued certificate as well as the template. Keep these identity fields separate from the certificate’s issuer, purposes, validity, and trust-chain checks.\n\n## DSE recommendation\n\nHave the PKI and network-access owners review the intended Subject and UPN population before enrolling pilot identities. Record the template version, enrollment scope, and expected certificate fields. Use a dedicated test server or user so the resulting certificate can be inspected without changing an entire deployment. Preserve the prior template configuration and document any requested correction.\n\n## Verification\n\nExamine the issued certificate and compare its Subject or user UPN field with the approved identity. Confirm the intended server certificate is available in NPS and exercise the selected authentication method with the pilot. Record missing fields and selection failures separately from other chain-validation errors before widening enrollment.\n\n## Official references\n\n[Microsoft Learn: Configure Certificate Templates for PEAP and EAP requirements](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-manage-cert-requirements). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-232-check-the-subject-and-user-name-fields-in-nps-certificate-templates/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-232-check-the-subject-and-user-name-fields-in-nps-certificate-templates/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-232-check-the-subject-and-user-name-fields-in-nps-certificate-templates/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Check the subject and user-name fields in NPS certificate templates",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-232-check-the-subject-and-user-name-fields-in-nps-certificate-templates/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-232-check-the-subject-and-user-name-fields-in-nps-certificate-templates/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-232-check-the-subject-and-user-name-fields-in-nps-certificate-templates/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-232-check-the-subject-and-user-name-fields-in-nps-certificate-templates/",
                "headline": "Check the subject and user-name fields in NPS certificate templates",
                "description": "Which identity fields must be populated for the documented NPS server and user certificates?",
                "abstract": "Which identity fields must be populated for the documented NPS server and user certificates?",
                "articleBody": "Source facts\nMicrosoft says an NPS server certificate with a blank Subject is unavailable for NPS authentication. Its template instructions choose a Subject name format other than None and build the name from directory information. For user certificates, the documented client requirement places the user principal name in the Subject Alternative Name extension. Microsoft Learn.\nApplicability\nIdentify whether the template issues a server or user certificate and review the complete requirements for the chosen authentication method. Inspect an actual issued certificate as well as the template. Keep these identity fields separate from the certificate’s issuer, purposes, validity, and trust-chain checks.\nDSE recommendation\nHave the PKI and network-access owners review the intended Subject and UPN population before enrolling pilot identities. Record the template version, enrollment scope, and expected certificate fields. Use a dedicated test server or user so the resulting certificate can be inspected without changing an entire deployment. Preserve the prior template configuration and document any requested correction.\nVerification\nExamine the issued certificate and compare its Subject or user UPN field with the approved identity. Confirm the intended server certificate is available in NPS and exercise the selected authentication method with the pilot. Record missing fields and selection failures separately from other chain-validation errors before widening enrollment.\nOfficial references\nMicrosoft Learn: Configure Certificate Templates for PEAP and EAP requirements. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:13:19+00:00",
                "dateModified": "2026-09-08T18:29:34+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-232-check-the-subject-and-user-name-fields-in-nps-certificate-templates/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-232-check-the-subject-and-user-name-fields-in-nps-certificate-templates/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Check the subject and user-name fields in NPS certificate templates"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 222,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure Certificate Templates for PEAP and EAP requirements",
                    "url": "https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-manage-cert-requirements"
                }
            }
        ]
    }
}