6.5.3 Network Policy Server

Update the intended NPS policies without changing unrelated EAP certificates

The Network Policy Server (NPS / RADIUS) template updates the PEAP or EAP-TLS server certificate stored inside an NPS network policy.

Policy selection

Enter policy names exactly as they appear under Policies > Network Policies in the NPS console. Separate several names with commas, or enter * to update every policy that has an EAP certificate configured.

Use explicit policy names when one NPS server hosts policies for different certificate identities. The template changes only the selected policies.

Ambiguous policies

The template does not change a policy that contains two different EAP certificates because it cannot determine which certificate the deployment owns.

  • When the ambiguous policy was named explicitly, the deployment fails.
  • When * was used, the deployment skips the policy and lists it in the output.

Resolve the duplicate certificate configuration in NPS or target an unambiguous policy before retrying.

Configuration export and service restart

NPS stores EAP certificate bindings in its exported configuration. The template:

  1. Exports the NPS configuration on the agent host.
  2. Rewrites the selected policy certificate thumbprints.
  3. Imports the updated configuration.
  4. Removes the temporary export.
  5. Restarts the NPS service.

The temporary export contains RADIUS shared secrets. It remains on the host during the operation and is removed by the template. Use a deployment window because the NPS service restart briefly interrupts authentication.

For a product overview, see certificate automation for Network Policy Server.