# Trace how NPS interprets and rewrites a user realm

> Which realm does NPS use before processing or forwarding a RADIUS request?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-168-trace-how-nps-interprets-and-rewrites-a-user-realm/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:14:23+00:00
- Modified: 2026-09-08T18:26:31+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Which realm does NPS use before processing or forwarding a RADIUS request?

## Potentially affected

Administrators reviewing realm handling in Network Policy Server connection request policies.

## DSE recommendation

For each approved format, write the expected realm and any transformation explicitly.

## Article

## Source facts

A RADIUS User-Name commonly carries both an account name and its account location, which Microsoft calls the realm. NPS can rewrite User-Name using regular-expression attribute rules before handling the request locally or forwarding it. Microsoft explicitly excludes PEAP from realm manipulation support. When a supplied user name has no domain, NPS ordinarily supplies the domain to which the NPS computer belongs. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-crp-realm-names).

## Applicability

Confirm the authentication method first; do not plan realm rewriting for PEAP. Collect the user-name formats expected from each access device, using sanitized examples. Separate the name entered by the user from the names received by NPS and presented to the destination server.

## DSE recommendation

For each approved format, write the expected realm and any transformation explicitly. Ask the identity and network-access owners to approve the mapping together. Include an unqualified name and a deliberately unexpected realm in the test set. Keep rules narrow, preserve their order and previous expressions, and avoid treating a successful request from one format as proof that all formats route correctly.

## Verification

Trace representative requests through the applicable connection request policy. Compare the received and forwarded identities with the approved mapping and record the selected destination. Investigate unexpected defaults, truncation, or changed user names before expanding the rule. Store only sanitized identity examples in ordinary change records.

## Official references

[Microsoft Learn: Realm Names](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-crp-realm-names). Source reviewed September 8, 2026.

## Primary reference

- Name: Realm Names
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-crp-realm-names
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Trace how NPS interprets and rewrites a user realm,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-168-trace-how-nps-interprets-and-rewrites-a-user-realm/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
