What you need to know
Which identity fields must be populated for the documented NPS server and user certificates?
Potentially affected
Administrators preparing AD CS certificate templates for PEAP and EAP network authentication.
DSE recommendation
Have the PKI and network-access owners review the intended Subject and UPN population before enrolling pilot identities.
Source facts
Microsoft says an NPS server certificate with a blank Subject is unavailable for NPS authentication. Its template instructions choose a Subject name format other than None and build the name from directory information. For user certificates, the documented client requirement places the user principal name in the Subject Alternative Name extension. Microsoft Learn.
Applicability
Identify whether the template issues a server or user certificate and review the complete requirements for the chosen authentication method. Inspect an actual issued certificate as well as the template. Keep these identity fields separate from the certificate’s issuer, purposes, validity, and trust-chain checks.
DSE recommendation
Have the PKI and network-access owners review the intended Subject and UPN population before enrolling pilot identities. Record the template version, enrollment scope, and expected certificate fields. Use a dedicated test server or user so the resulting certificate can be inspected without changing an entire deployment. Preserve the prior template configuration and document any requested correction.
Verification
Examine the issued certificate and compare its Subject or user UPN field with the approved identity. Confirm the intended server certificate is available in NPS and exercise the selected authentication method with the pilot. Record missing fields and selection failures separately from other chain-validation errors before widening enrollment.
Official references
Microsoft Learn: Configure Certificate Templates for PEAP and EAP requirements. Source reviewed September 8, 2026.
Review the official source
Configure Certificate Templates for PEAP and EAP requirements · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE