# Plan NPS server certificates even when Wi-Fi users authenticate with passwords

> Why does the password-based 802.1X wireless design still require NPS certificates?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-063-plan-nps-server-certificates-even-when-wi-fi-users-authenticate-with-passwords/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:16:08+00:00
- Modified: 2026-09-08T18:20:22+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Why does the password-based 802.1X wireless design still require NPS certificates?

## Potentially affected

Use this review for the documented password-based wireless design and supported client population.

## DSE recommendation

Keep the user credential decision separate from the authentication-server certificate plan.

## Article

## Source facts

The documented PEAP-MS-CHAP v2 design uses password credentials for user authentication. That same deployment guide still requires server certificates on the authenticating NPS servers. Microsoft identifies an internal AD CS deployment or a public certification authority as options for issuing those server certificates. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/wireless/a-deploy-8021X-wireless-access).

## Applicability

Use this review for the documented password-based wireless design and supported client population. Identify every authenticating NPS server, its certificate source, and the client trust configuration. Review current authentication guidance before selecting this method.

## DSE recommendation

Keep the user credential decision separate from the authentication-server certificate plan. Have the wireless, identity, and certificate owners review the expected server identities and trust anchors together. Record who will renew each NPS certificate and how a replacement will be tested. Include a deliberately untrusted server identity in the approved client-validation test plan.

## Verification

Test a representative client against the intended NPS service and inspect the server certificate involved. Verify the approved behavior when server identity or trust does not match the client configuration. Preserve the connection result and certificate identity without capturing user passwords. Resolve a validation or renewal gap before expanding wireless enrollment.

## Official references

[Microsoft Learn: Deploy Password-Based 802.1X Authenticated Wireless Access](https://learn.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/wireless/a-deploy-8021X-wireless-access). Source reviewed September 8, 2026.

## Primary reference

- Name: Deploy Password-Based 802.1X Authenticated Wireless Access
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/wireless/a-deploy-8021X-wireless-access
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Plan NPS server certificates even when Wi-Fi users authenticate with passwords,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-063-plan-nps-server-certificates-even-when-wi-fi-users-authenticate-with-passwords/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
