What you need to know
Why does the password-based 802.1X wireless design still require NPS certificates?
Potentially affected
Use this review for the documented password-based wireless design and supported client population.
DSE recommendation
Keep the user credential decision separate from the authentication-server certificate plan.
Source facts
The documented PEAP-MS-CHAP v2 design uses password credentials for user authentication. That same deployment guide still requires server certificates on the authenticating NPS servers. Microsoft identifies an internal AD CS deployment or a public certification authority as options for issuing those server certificates. Microsoft documentation.
Applicability
Use this review for the documented password-based wireless design and supported client population. Identify every authenticating NPS server, its certificate source, and the client trust configuration. Review current authentication guidance before selecting this method.
DSE recommendation
Keep the user credential decision separate from the authentication-server certificate plan. Have the wireless, identity, and certificate owners review the expected server identities and trust anchors together. Record who will renew each NPS certificate and how a replacement will be tested. Include a deliberately untrusted server identity in the approved client-validation test plan.
Verification
Test a representative client against the intended NPS service and inspect the server certificate involved. Verify the approved behavior when server identity or trust does not match the client configuration. Preserve the connection result and certificate identity without capturing user passwords. Resolve a validation or renewal gap before expanding wireless enrollment.
Official references
Microsoft Learn: Deploy Password-Based 802.1X Authenticated Wireless Access. Source reviewed September 8, 2026.
Review the official source
Deploy Password-Based 802.1X Authenticated Wireless Access · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE