# Update NPS policy certificate bindings after certificate expiration

> How should administrators confirm that each NPS policy references the intended current certificate?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-188-update-nps-policy-certificate-bindings-after-certificate-expiration/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:14:03+00:00
- Modified: 2026-09-08T18:26:32+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

How should administrators confirm that each NPS policy references the intended current certificate?

## Potentially affected

Administrators maintaining certificate-based NPS authentication policies, distinguishing manual certificate updates from autoenrollment.

## DSE recommendation

Maintain a policy-to-certificate mapping and assign renewal follow-up to the authentication owner.

## Article

## Source facts

Microsoft states that the server certificate bound to an NPS network policy is not automatically replaced when it expires. An administrator must update each policy using certificate-based authentication to select a current certificate. Until that binding is updated, affected clients cannot authenticate successfully through the policy. Certificate autoenrollment is the exception: it renews the server certificate before expiration, and NPS uses the renewed certificate without a manual policy update. The guidance verifies a binding by comparing its returned thumbprint with the expected certificate in the local computer’s Personal store. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-manage-certificates).

## Applicability

Inventory the NPS servers, enrollment method, certificate policies, thumbprints, and expiration dates. Confirm whether autoenrollment applies before scheduling manual replacement of a policy selection.

## DSE recommendation

Maintain a policy-to-certificate mapping and assign renewal follow-up to the authentication owner. Keep successful certificate enrollment separate from the policy-binding check. Have the PKI and NPS teams agree on the expected replacement identity before changing production policies.

## Verification

Inspect every affected binding and compare the thumbprint with the approved certificate. Test representative authentication through each policy and record the result and selected certificate identity. Reconcile any policy still referencing an expired certificate before closing the certificate-maintenance task.

## Official references

[Microsoft Learn: Manage Certificates Used with NPS](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-manage-certificates). Source reviewed September 8, 2026.

## Primary reference

- Name: Manage Certificates Used with NPS
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-manage-certificates
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Update NPS policy certificate bindings after certificate expiration,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-188-update-nps-policy-certificate-bindings-after-certificate-expiration/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
