Distinguish NPS revocation exceptions before changing the registry

Which NPS setting bypasses all client revocation checks versus an unavailable CRL service?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 1 min read
Executive summary

What you need to know

Which NPS setting bypasses all client revocation checks versus an unavailable CRL service?

Potentially affected

Administrators reviewing EAP-TLS revocation-check exceptions on NPS.

DSE recommendation

Ask the identity and PKI owners to document the reason for any exception, its scope, and the plan to repair the underlying validation path.

Source facts

Microsoft documents separate registry controls for different NPS certificate-revocation conditions. Enabling NoRevocationCheck prevents EAP-TLS from checking the client certificate for revocation. Enabling IgnoreRevocationOffline allows EAP-TLS clients to connect when the network server holding the CRL is unavailable. Microsoft Learn.

Applicability

Inventory the effective exception values and the actual certificate-validation failure before proposing a change. Separate a revoked credential from a failure to reach revocation information. Review the source definition of the selected value rather than inferring behavior from a similar registry name.

DSE recommendation

Ask the identity and PKI owners to document the reason for any exception, its scope, and the plan to repair the underlying validation path. Preserve the initial settings and relevant authentication events. Use a controlled test with a dedicated certificate set before changing production behavior. Keep any exception time-bounded and assigned to an owner who can remove it after repair.

Verification

Test valid, revoked, and unavailable-CRL conditions according to the approved laboratory plan. Compare NPS decisions with the intended exception semantics and record each outcome separately. Verify that repairing CRL access permits removal of the exception. Do not treat a newly successful connection as evidence that revocation validation remains intact.

Official references

Microsoft Learn: Configure Network Policy Server Certificate Revocation List registry settings for Windows Server. Source reviewed September 8, 2026.

Primary reference

Review the official source

Configure Network Policy Server Certificate Revocation List registry settings for Windows Server · Verified September 8, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE