Update NPS policy certificate bindings after certificate expiration

How should administrators confirm that each NPS policy references the intended current certificate?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 1 min read
Executive summary

What you need to know

How should administrators confirm that each NPS policy references the intended current certificate?

Potentially affected

Administrators maintaining certificate-based NPS authentication policies, distinguishing manual certificate updates from autoenrollment.

DSE recommendation

Maintain a policy-to-certificate mapping and assign renewal follow-up to the authentication owner.

Source facts

Microsoft states that the server certificate bound to an NPS network policy is not automatically replaced when it expires. An administrator must update each policy using certificate-based authentication to select a current certificate. Until that binding is updated, affected clients cannot authenticate successfully through the policy. Certificate autoenrollment is the exception: it renews the server certificate before expiration, and NPS uses the renewed certificate without a manual policy update. The guidance verifies a binding by comparing its returned thumbprint with the expected certificate in the local computer’s Personal store. Microsoft documentation.

Applicability

Inventory the NPS servers, enrollment method, certificate policies, thumbprints, and expiration dates. Confirm whether autoenrollment applies before scheduling manual replacement of a policy selection.

DSE recommendation

Maintain a policy-to-certificate mapping and assign renewal follow-up to the authentication owner. Keep successful certificate enrollment separate from the policy-binding check. Have the PKI and NPS teams agree on the expected replacement identity before changing production policies.

Verification

Inspect every affected binding and compare the thumbprint with the approved certificate. Test representative authentication through each policy and record the result and selected certificate identity. Reconcile any policy still referencing an expired certificate before closing the certificate-maintenance task.

Official references

Microsoft Learn: Manage Certificates Used with NPS. Source reviewed September 8, 2026.

Primary reference

Review the official source

Manage Certificates Used with NPS · Verified September 8, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE