# Check that NPS can select an auto-enrolled server certificate

> How can an NPS administrator verify an enrolled certificate without leaving a test policy behind?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-140-check-that-nps-can-select-an-auto-enrolled-server-certificate/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:14:51+00:00
- Modified: 2026-09-08T18:23:27+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

How can an NPS administrator verify an enrolled certificate without leaving a test policy behind?

## Potentially affected

Administrators checking NPS server certificates after configuring certificate auto-enrollment.

## DSE recommendation

Record the expected certificate identity and have the PKI and authentication owners review it together.

## Article

## Source facts

Microsoft’s NPS auto-enrollment procedure uses Group Policy to manage certificate issuance and renewal in an Active Directory environment. After refreshing policy, its verification procedure begins a test network-policy workflow so NPS can confirm that the enrolled certificate is usable for authentication. The administrator does not finish that wizard. Consequently, the certificate can be checked without creating the test network policy. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/server-certs/configure-server-certificate-auto-enrollment).

## Applicability

Identify the NPS server, certificate template, policy scope, issuing authority, and intended authentication method. Review the source’s enrollment prerequisites and confirm that the certificate being inspected belongs to the intended server.

## DSE recommendation

Record the expected certificate identity and have the PKI and authentication owners review it together. Follow the documented inspection workflow, noting where the wizard must be cancelled. Keep certificate inspection separate from approval of any new access policy.

## Verification

Confirm that the expected certificate is offered and accepted in the relevant NPS authentication configuration. Cancel the temporary workflow and verify that no unintended policy was left behind. Then conduct the approved authentication test and preserve the certificate identity and result without recording private-key material.

## Official references

[Microsoft Learn: Configure Certificate Auto-Enrollment for Network Policy Server](https://learn.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/server-certs/configure-server-certificate-auto-enrollment). Source reviewed September 8, 2026.

## Primary reference

- Name: Configure Certificate Auto-Enrollment for Network Policy Server
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/server-certs/configure-server-certificate-auto-enrollment
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check that NPS can select an auto-enrolled server certificate,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-140-check-that-nps-can-select-an-auto-enrolled-server-certificate/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
