Configure NPS for 802.1X with AD Credentials: A Practical Guide
Learn how to configure Microsoft’s Network Policy Server (NPS) as a RADIUS server for 802.1X authentication using Active Directory credentials, with a step‑by‑step guide, example commands, troubleshooting tips, and common pitfalls to avoid.
13 Mar 2026, 20:55 UTC

Why NPS Matters for 802.1X
When you need wired or wireless devices to authenticate against the same Active Directory (AD) that powers your Windows logons, Microsoft’s Network Policy Server (NPS) is the built‑in RADIUS solution. It lets you enforce conditions—user group membership, IP ranges, or EAP methods—before granting network access.
Quick Takeaway
To enable 802.1X on a switch or AP using AD credentials, install the NPS role, add the device as a RADIUS client, create a connection‑request policy, and then a network policy that selects the desired EAP method. Verify with the built‑in test dialog and check the Event Log for details.
Step‑by‑Step Configuration
1. Install the NPS Role
Open Server Manager → Add Roles and Features → select Network Policy and Access Services. After installation, launch the NPS console.
2. Register NPS in AD
In the console, right‑click NPS (Local) and choose Register server in Active Directory. This allows NPS to query AD for user accounts.
3. Define the RADIUS Client
In the console, expand RADIUS Clients and Servers → RADIUS Clients and click Add. Provide a name, IP address, and a shared secret. The secret must match the configuration on the switch/AP.
# Run on the NPS host (requires administrative rights)
netsh nps add client name=Switch1 ipaddress=192.168.1.10 secret=MySecret
Replace MySecret with a strong, unique string.
4. Create a Connection‑Request Policy
This policy determines whether the RADIUS request should be forwarded to AD. A typical policy allows all requests from the defined client and passes them to the next policy.
5. Create a Network Policy for 802.1X
Navigate to Network Policies → Add. Set the policy name, and under Conditions add:
- Authentication Type:
EAP - User Groups:
Domain Users(or a narrower group) - Connection Request Type:
Microsoft: Network (EAP)
Under Constraints, choose the EAP method: EAP‑TLS, EAP‑PEAP, or MS‑CHAPv2. For EAP‑TLS, upload a server certificate issued by a trusted CA.
6. Test the Setup
In the NPS console, right‑click the policy and choose Test Connection Request. Enter a valid AD username and password. If the test succeeds, the policy is correctly configured.
Checking the Event Log
Authentication events are logged under:
Applications and Services Logs → Microsoft → Windows → NPS → Operational
Look for event IDs 6275 (success) or 6274 (failure). The log includes the client IP, user name, and failure reason if applicable.
Common Pitfalls and Limits
Policy Order Matters
NPS evaluates policies top‑to‑bottom. A broad “Allow all users” policy above a stricter one will override it. Place the most restrictive policies first.
Weak EAP Methods
MS‑CHAPv2 exposes credentials to downgrade attacks. Prefer EAP‑TLS or PEAP with strong inner authentication (e.g., MS‑CHAPv2 with EAP‑TLS).
Domain‑Joined Requirement
If the NPS host isn’t joined to the domain, it cannot query AD and all authentications fail.
Shared Secret Mismatch
Even a single character difference between the NPS secret and the device secret results in silent failures. Verify both sides match exactly.
Logging Disabled
Without Event Log entries, troubleshooting is nearly impossible. Ensure the NPS Operational log is enabled.
Overly Permissive Policies
A policy that allows all users can inadvertently grant network access to compromised accounts. Always restrict to the minimum necessary group.
Practical Verification Checklist
- Confirm the NPS role is installed and the server is AD‑joined.
- Verify the RADIUS client IP matches the device’s IP.
- Ensure the shared secret is identical on both sides.
- Run a Test Connection Request for a known good account.
- Check the Operational log for event ID 6275.
- Inspect the policy order: the most restrictive policy should be first.
When to Use NPS vs. Third‑Party RADIUS
For environments already using Windows Server and AD, NPS offers tight integration and no extra licensing. Third‑party RADIUS servers (e.g., FreeRADIUS) become attractive when you need cross‑platform authentication or advanced features like RADIUS accounting.
Conclusion
Setting up NPS for 802.1X is a straightforward process that leverages existing AD credentials. By carefully ordering policies, choosing strong EAP methods, and validating via the test dialog and Event Log, you can secure wired and wireless access with minimal overhead.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.