# Register the RADIUS-speaking access device, not the end-user computer

> Which system is the RADIUS client that NPS should be configured to receive requests from?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-194-register-the-radius-speaking-access-device-not-the-end-user-computer/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:13:57+00:00
- Modified: 2026-09-08T18:26:32+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Which system is the RADIUS client that NPS should be configured to receive requests from?

## Potentially affected

Administrators identifying RADIUS clients for Network Policy Server.

## DSE recommendation

Create an inventory of the message-sending devices and the NPS servers that should receive from them.

## Article

## Source facts

Microsoft defines a network access server using RADIUS as a RADIUS client: it sends connection requests and accounting messages to the server. An NPS configured as a forwarding proxy is also a RADIUS client of the downstream server. Adding a RADIUS client to NPS configures it to receive Access-Request messages from that access server or proxy. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-radius-clients).

## Applicability

Trace one connection request from the user’s device through the access infrastructure to NPS. Identify whether a wireless access point, VPN server, switch, or proxy actually sends the RADIUS message.

## DSE recommendation

Create an inventory of the message-sending devices and the NPS servers that should receive from them. Have network-access and authentication owners review the source addresses and device identities. Document proxy hops separately and handle any shared authentication material through the approved protected process.

## Verification

Generate a controlled connection attempt and correlate the sending device with the NPS request record. Confirm that the configured client represents that device or proxy and test an unapproved sender in an authorized environment. Resolve an identity or address mismatch before accepting the client registration.

## Official references

[Microsoft Learn: RADIUS Clients](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-radius-clients). Source reviewed September 8, 2026.

## Primary reference

- Name: RADIUS Clients
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-radius-clients
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Register the RADIUS-speaking access device, not the end-user computer,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-194-register-the-radius-speaking-access-device-not-the-end-user-computer/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
