What you need to know
What group membership and server preferences should be planned for NPS proxy load balancing?
Potentially affected
Administrators distributing RADIUS requests through NPS proxies.
DSE recommendation
Write the proposed membership and preference settings in a table owned by the authentication team.
Source facts
NPS proxy load balancing requires more than one RADIUS server in a remote server group. Microsoft calls for a deployment plan covering the required groups, their members, and each server’s Priority and Weight settings. The guidance also describes sending client requests to two proxies and having those proxies distribute work among backend RADIUS servers, providing paths at both tiers. Microsoft documentation.
Applicability
Inventory the network access servers, proxy addresses, remote groups, backend capacity, and authentication requirements. Review which servers are equivalent destinations before placing them in one distribution group.
DSE recommendation
Write the proposed membership and preference settings in a table owned by the authentication team. Ask the network-access owners to confirm the proxy destinations configured on their devices. Define expected behavior when a backend or proxy is unavailable, including who will investigate an authentication surge.
Verification
Generate controlled requests from representative access devices and examine which proxy and backend handled them. Repeat with one approved unavailable component at a time. Compare the observed distribution and authentication results with the plan; resolve an unreachable group member before relying on the arrangement for continuity.
Official references
Microsoft Learn: NPS Proxy Server Load Balancing. Source reviewed September 8, 2026.
Review the official source
NPS Proxy Server Load Balancing · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE