What you need to know
Which domain permissions and access-device capabilities must be checked when NPS acts as the RADIUS server?
Potentially affected
Administrators planning NPS as the authentication and authorization server.
DSE recommendation
Build a matrix of user domain, NPS instance, access-device type, and selected method.
Source facts
Microsoft’s server-planning guidance requires choosing the domain membership of NPS. To read user dial-in properties during authorization, it directs administrators to add the NPS computer account to the RAS and NPSs group in each relevant domain. NPS supports password and certificate authentication methods, but network access servers do not all support the same methods. The method may therefore differ by access type. Microsoft documentation.
Applicability
Identify the user domains, NPS computer account, trust arrangement, access devices, and proposed authentication methods. Review the source’s precise domain requirements before granting directory access.
DSE recommendation
Build a matrix of user domain, NPS instance, access-device type, and selected method. Have directory and network-access owners review permissions and compatibility independently. Document which requests NPS will process locally and which belong to a separately designed proxy path.
Verification
Test an authorized representative account from each relevant domain through each intended device type. Inspect the authentication and authorization results and verify the selected method. Preserve a directory-read failure separately from an access-device compatibility failure, and resolve both before expanding the service.
Official references
Microsoft Learn: Plan NPS as a RADIUS server. Source reviewed September 8, 2026.
Review the official source
Plan NPS as a RADIUS server · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE