What you need to know
Which system is the RADIUS client that NPS should be configured to receive requests from?
Potentially affected
Administrators identifying RADIUS clients for Network Policy Server.
DSE recommendation
Create an inventory of the message-sending devices and the NPS servers that should receive from them.
Source facts
Microsoft defines a network access server using RADIUS as a RADIUS client: it sends connection requests and accounting messages to the server. An NPS configured as a forwarding proxy is also a RADIUS client of the downstream server. Adding a RADIUS client to NPS configures it to receive Access-Request messages from that access server or proxy. Microsoft documentation.
Applicability
Trace one connection request from the user’s device through the access infrastructure to NPS. Identify whether a wireless access point, VPN server, switch, or proxy actually sends the RADIUS message.
DSE recommendation
Create an inventory of the message-sending devices and the NPS servers that should receive from them. Have network-access and authentication owners review the source addresses and device identities. Document proxy hops separately and handle any shared authentication material through the approved protected process.
Verification
Generate a controlled connection attempt and correlate the sending device with the NPS request record. Confirm that the configured client represents that device or proxy and test an unapproved sender in an authorized environment. Resolve an identity or address mismatch before accepting the client registration.
Official references
Microsoft Learn: RADIUS Clients. Source reviewed September 8, 2026.
Review the official source
RADIUS Clients · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE