# Preserve long NPS expressions outside the console editor

> How can an NPS expression longer than 256 characters be maintained without invalidating it?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-050-preserve-long-nps-expressions-outside-the-console-editor/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:16:21+00:00
- Modified: 2026-09-08T18:17:14+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

How can an NPS expression longer than 256 characters be maintained without invalidating it?

## Potentially affected

Use this review when an approved NPS expression approaches or exceeds the graphical editor limit.

## DSE recommendation

Keep the approved expression in a controlled change record and choose the documented command-based route when required.

## Article

## Source facts

NPS supports regular expressions for network-policy attribute conditions and RADIUS realms. NPS console and MMC string fields have a 256-character entry limit, including regular-expression settings. Microsoft directs administrators to NETSH NPS commands for longer values. Editing an already configured longer value through those graphical tools invalidates it. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-crp-reg-expressions).

## Applicability

Use this review when an approved NPS expression approaches or exceeds the graphical editor limit. Identify the exact policy field, current expression, character count, and intended maintenance interface before changing the value.

## DSE recommendation

Keep the approved expression in a controlled change record and choose the documented command-based route when required. Have another administrator compare the complete proposed value with that record. Review escaping, anchors, and the expected matches against the source syntax reference. Document that later graphical editing is excluded for this long-value configuration.

## Verification

Inspect the configured value after the approved change and compare it character for character with the reviewed expression. Run representative matching and nonmatching inputs without altering the intended authentication design. Preserve the command, sanitized observations, and full expression for the next operator. Resolve truncation or unexpected modification before accepting the change.

## Official references

[Microsoft Learn: Use Regular Expressions in NPS](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-crp-reg-expressions). Source reviewed September 8, 2026.

## Primary reference

- Name: Use Regular Expressions in NPS
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-crp-reg-expressions
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Preserve long NPS expressions outside the console editor,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-050-preserve-long-nps-expressions-outside-the-console-editor/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
