Knowledge Base

How is the Server Certificate installed on Microsoft Network Policy Server (NPS) on Windows 2019 Server? 

How is the Server Certificate installed on Microsoft Network Policy Server (NPS) on Windows 2019 Server? 
 
Overview: 

This guide provides step-by-step instructions for installing and applying a server certificate within Microsoft Network Policy Server (NPS) on Windows Server 2019. This ensures secure authentication for network access policies, particularly when using EAP-based authentication methods.

Prerequisites 

Before you begin, ensure you have the following: 

  • Administrator access to the Windows Server 2019 machine. 

  • The server certificate is already installed on the machine (visible in the certificate store). 

  • Access to the Network Policy Server (NPS) role installed on the server. 
     

Procedure: 

Step 1: Open Network Policy Server 

Open the Network Policy Server console by navigating to: 
Windows Icon → Administrative Tools → Network Policy Server. 
Alternatively, access it via Server Manager → Tools → Network Policy Server. 

 
 

(Or) 

 

 

Step 2: Navigate to Network Policies 

When the NPS console opens, go to: 
Policies → Network Policies. 
In the right pane, you should see the list of configured Network Policy profiles. 

 

 

 

Step 3: Open the Policy Properties 

Double‑click the desired Network Policy profile or right‑click it and select Properties to open the policy settings. 
 

 

 

Step 4: Edit the EAP Authentication Method 

Select the Constraints tab, then click Edit for the configured EAP types. 
This opens the Edit Protected EAP Properties window. 

 

 

 

Step 5: Select the Server Certificate 

In the Edit Protected EAP Properties window, choose the appropriate certificate from the Certificate issued dropdown list. 
If the certificate has been installed correctly, it should appear in the list. 
Click OK, then Apply to save your changes. 

 

 

 

Step 6: Restart NPS 

Stop and restart the Network Policy Server service to ensure the certificate is applied properly. 

 

  

 

Verification 

To confirm the server certificate has been correctly applied: 

  • Reopen the EAP properties of the Network Policy and verify that the selected certificate is still displayed in the dropdown. 

  • Test authentication from a client device to ensure successful certificate‑based authentication without warnings. 

 
 
 
Related Articles:  
Tags: 

Need assistance?

Contact our team for help with your purchase or issuing your certificate.

Live chat

Call us today