Trace local and forwarded requests through ordered NPS policies

How does a mixed-role NPS choose between local processing and proxy forwarding?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

How does a mixed-role NPS choose between local processing and proxy forwarding?

Potentially affected

Administrators configuring NPS connection request policies for local and remote processing.

DSE recommendation

Build a small decision table containing a request that should be forwarded, one that should stay local, and one that should match neither policy.

Source facts

Microsoft documents an NPS instance acting as both a RADIUS server and a proxy through connection request policies. In its mixed-role example, the forwarding policy is evaluated before the default local-processing policy. A request matching the first policy is forwarded; one matching only the default is processed locally; a request matching neither is discarded. Microsoft Learn.

Applicability

Identify each intended request population and its destination before editing policy order. Separate the decision about where a request is processed from the downstream decision about whether access is authorized. Include the actual access devices and identity formats in the review.

DSE recommendation

Build a small decision table containing a request that should be forwarded, one that should stay local, and one that should match neither policy. Record the policy order and the expected processing location for each. Have the local and remote RADIUS owners agree on these results before the change. Preserve the original ordering and conditions so an unexpected routing result can be reversed.

Verification

Send the approved test requests and correlate the chosen policy with the server that handled them. Confirm the unmatched case receives the intended outcome and does not reach an unintended destination. Record authorization results separately from routing results so a successful login cannot conceal a request processed on the wrong server.

Official references

Microsoft Learn: Connection Request Policies. Source reviewed September 8, 2026.

Primary reference

Review the official source

Connection Request Policies · Verified September 8, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE