What you need to know
How can an NPS administrator verify an enrolled certificate without leaving a test policy behind?
Potentially affected
Administrators checking NPS server certificates after configuring certificate auto-enrollment.
DSE recommendation
Record the expected certificate identity and have the PKI and authentication owners review it together.
Source facts
Microsoft’s NPS auto-enrollment procedure uses Group Policy to manage certificate issuance and renewal in an Active Directory environment. After refreshing policy, its verification procedure begins a test network-policy workflow so NPS can confirm that the enrolled certificate is usable for authentication. The administrator does not finish that wizard. Consequently, the certificate can be checked without creating the test network policy. Microsoft documentation.
Applicability
Identify the NPS server, certificate template, policy scope, issuing authority, and intended authentication method. Review the source’s enrollment prerequisites and confirm that the certificate being inspected belongs to the intended server.
DSE recommendation
Record the expected certificate identity and have the PKI and authentication owners review it together. Follow the documented inspection workflow, noting where the wizard must be cancelled. Keep certificate inspection separate from approval of any new access policy.
Verification
Confirm that the expected certificate is offered and accepted in the relevant NPS authentication configuration. Cancel the temporary workflow and verify that no unintended policy was left behind. Then conduct the approved authentication test and preserve the certificate identity and result without recording private-key material.
Official references
Microsoft Learn: Configure Certificate Auto-Enrollment for Network Policy Server. Source reviewed September 8, 2026.
Review the official source
Configure Certificate Auto-Enrollment for Network Policy Server · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE