# Protect an NPS configuration export and review its import limits

> What must be reviewed before importing an exported NPS configuration?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-212-protect-an-nps-configuration-export-and-review-its-import-limits/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:13:39+00:00
- Modified: 2026-09-08T18:29:33+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

What must be reviewed before importing an exported NPS configuration?

## Potentially affected

Administrators moving Network Policy Server settings between Windows servers.

## DSE recommendation

Store the export in an access-controlled location and name the administrators authorized to handle it.

## Article

## Source facts

Importing an NPS configuration replaces the destination settings rather than merging with them. Microsoft prohibits this procedure when the source NPS database version is newer than the destination database. SQL Server logging settings are excluded from the export and must be configured manually on the receiving NPS. A Netsh export contains unencrypted RADIUS shared secrets in its XML file. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-manage-export).

## Applicability

Identify the source and destination roles and verify the supported export and import method for their server versions. Review the complete configuration scope before treating the file as a single-policy backup. Account for server-specific endpoints and logging destinations in the transfer plan.

## DSE recommendation

Store the export in an access-controlled location and name the administrators authorized to handle it. Record the source configuration and capture the destination’s current settings before import. Have the receiving owner review clients, remote servers, policy order, and logging configuration for that environment. Use a nonproduction transfer exercise before replacing settings on an active authentication server.

## Verification

Refresh the management view and compare the imported settings with the approved transfer inventory. Test representative local and forwarded requests, accounting where applicable, and a request that should be rejected. Record the configuration differences and functional results separately. Remove temporary transfer access according to the approved handling plan once the import is accepted.

## Official references

[Microsoft Learn: Export an NPS Configuration for Import on Another Server](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-manage-export). Source reviewed September 8, 2026.

## Primary reference

- Name: Export an NPS Configuration for Import on Another Server
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-manage-export
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Protect an NPS configuration export and review its import limits,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-212-protect-an-nps-configuration-export-and-review-its-import-limits/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
