What you need to know
Which realm does NPS use before processing or forwarding a RADIUS request?
Potentially affected
Administrators reviewing realm handling in Network Policy Server connection request policies.
DSE recommendation
For each approved format, write the expected realm and any transformation explicitly.
Source facts
A RADIUS User-Name commonly carries both an account name and its account location, which Microsoft calls the realm. NPS can rewrite User-Name using regular-expression attribute rules before handling the request locally or forwarding it. Microsoft explicitly excludes PEAP from realm manipulation support. When a supplied user name has no domain, NPS ordinarily supplies the domain to which the NPS computer belongs. Microsoft Learn.
Applicability
Confirm the authentication method first; do not plan realm rewriting for PEAP. Collect the user-name formats expected from each access device, using sanitized examples. Separate the name entered by the user from the names received by NPS and presented to the destination server.
DSE recommendation
For each approved format, write the expected realm and any transformation explicitly. Ask the identity and network-access owners to approve the mapping together. Include an unqualified name and a deliberately unexpected realm in the test set. Keep rules narrow, preserve their order and previous expressions, and avoid treating a successful request from one format as proof that all formats route correctly.
Verification
Trace representative requests through the applicable connection request policy. Compare the received and forwarded identities with the approved mapping and record the selected destination. Investigate unexpected defaults, truncation, or changed user names before expanding the rule. Store only sanitized identity examples in ordinary change records.
Official references
Microsoft Learn: Realm Names. Source reviewed September 8, 2026.
Review the official source
Realm Names · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE