# Define NPS proxy server groups before distributing authentication load

> What group membership and server preferences should be planned for NPS proxy load balancing?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-126-define-nps-proxy-server-groups-before-distributing-authentication-load/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:15:05+00:00
- Modified: 2026-09-08T18:23:27+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

What group membership and server preferences should be planned for NPS proxy load balancing?

## Potentially affected

Administrators distributing RADIUS requests through NPS proxies.

## DSE recommendation

Write the proposed membership and preference settings in a table owned by the authentication team.

## Article

## Source facts

NPS proxy load balancing requires more than one RADIUS server in a remote server group. Microsoft calls for a deployment plan covering the required groups, their members, and each server’s Priority and Weight settings. The guidance also describes sending client requests to two proxies and having those proxies distribute work among backend RADIUS servers, providing paths at both tiers. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-manage-proxy-lb).

## Applicability

Inventory the network access servers, proxy addresses, remote groups, backend capacity, and authentication requirements. Review which servers are equivalent destinations before placing them in one distribution group.

## DSE recommendation

Write the proposed membership and preference settings in a table owned by the authentication team. Ask the network-access owners to confirm the proxy destinations configured on their devices. Define expected behavior when a backend or proxy is unavailable, including who will investigate an authentication surge.

## Verification

Generate controlled requests from representative access devices and examine which proxy and backend handled them. Repeat with one approved unavailable component at a time. Compare the observed distribution and authentication results with the plan; resolve an unreachable group member before relying on the arrangement for continuity.

## Official references

[Microsoft Learn: NPS Proxy Server Load Balancing](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-manage-proxy-lb). Source reviewed September 8, 2026.

## Primary reference

- Name: NPS Proxy Server Load Balancing
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-manage-proxy-lb
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Define NPS proxy server groups before distributing authentication load,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-126-define-nps-proxy-server-groups-before-distributing-authentication-load/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
