# Distinguish NPS revocation exceptions before changing the registry

> Which NPS setting bypasses all client revocation checks versus an unavailable CRL service?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-229-distinguish-nps-revocation-exceptions-before-changing-the-registry/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:13:22+00:00
- Modified: 2026-09-08T18:29:34+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Which NPS setting bypasses all client revocation checks versus an unavailable CRL service?

## Potentially affected

Administrators reviewing EAP-TLS revocation-check exceptions on NPS.

## DSE recommendation

Ask the identity and PKI owners to document the reason for any exception, its scope, and the plan to repair the underlying validation path.

## Article

## Source facts

Microsoft documents separate registry controls for different NPS certificate-revocation conditions. Enabling NoRevocationCheck prevents EAP-TLS from checking the client certificate for revocation. Enabling IgnoreRevocationOffline allows EAP-TLS clients to connect when the network server holding the CRL is unavailable. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/network-policy-server-certificate-revocation-list-check-registry-settings).

## Applicability

Inventory the effective exception values and the actual certificate-validation failure before proposing a change. Separate a revoked credential from a failure to reach revocation information. Review the source definition of the selected value rather than inferring behavior from a similar registry name.

## DSE recommendation

Ask the identity and PKI owners to document the reason for any exception, its scope, and the plan to repair the underlying validation path. Preserve the initial settings and relevant authentication events. Use a controlled test with a dedicated certificate set before changing production behavior. Keep any exception time-bounded and assigned to an owner who can remove it after repair.

## Verification

Test valid, revoked, and unavailable-CRL conditions according to the approved laboratory plan. Compare NPS decisions with the intended exception semantics and record each outcome separately. Verify that repairing CRL access permits removal of the exception. Do not treat a newly successful connection as evidence that revocation validation remains intact.

## Official references

[Microsoft Learn: Configure Network Policy Server Certificate Revocation List registry settings for Windows Server](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/network-policy-server-certificate-revocation-list-check-registry-settings). Source reviewed September 8, 2026.

## Primary reference

- Name: Configure Network Policy Server Certificate Revocation List registry settings for Windows Server
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/network-policy-server-certificate-revocation-list-check-registry-settings
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Distinguish NPS revocation exceptions before changing the registry,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-229-distinguish-nps-revocation-exceptions-before-changing-the-registry/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
