What you need to know
How should administrators confirm that each NPS policy references the intended current certificate?
Potentially affected
Administrators maintaining certificate-based NPS authentication policies, distinguishing manual certificate updates from autoenrollment.
DSE recommendation
Maintain a policy-to-certificate mapping and assign renewal follow-up to the authentication owner.
Source facts
Microsoft states that the server certificate bound to an NPS network policy is not automatically replaced when it expires. An administrator must update each policy using certificate-based authentication to select a current certificate. Until that binding is updated, affected clients cannot authenticate successfully through the policy. Certificate autoenrollment is the exception: it renews the server certificate before expiration, and NPS uses the renewed certificate without a manual policy update. The guidance verifies a binding by comparing its returned thumbprint with the expected certificate in the local computer’s Personal store. Microsoft documentation.
Applicability
Inventory the NPS servers, enrollment method, certificate policies, thumbprints, and expiration dates. Confirm whether autoenrollment applies before scheduling manual replacement of a policy selection.
DSE recommendation
Maintain a policy-to-certificate mapping and assign renewal follow-up to the authentication owner. Keep successful certificate enrollment separate from the policy-binding check. Have the PKI and NPS teams agree on the expected replacement identity before changing production policies.
Verification
Inspect every affected binding and compare the thumbprint with the approved certificate. Test representative authentication through each policy and record the result and selected certificate identity. Reconcile any policy still referencing an expired certificate before closing the certificate-maintenance task.
Official references
Microsoft Learn: Manage Certificates Used with NPS. Source reviewed September 8, 2026.
Review the official source
Manage Certificates Used with NPS · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE