Network Policy Server, the RADIUS server role in Windows Server. It often authenticates point-to-site VPN users against AD DS and hosts the NPS extension for Entra MFA.
Also called Network Policy Server.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains NPS in context, with comparison tables and the common traps.
Terms in this definition
- RADIUS authentication
Way of authenticating point-to-site VPN users where the gateway passes credentials on to a RADIUS server, NPS for example, which validates them against on-premises AD DS.
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Point-to-site VPN
Connection type in which single client machines, rather than whole sites, tunnel into an Azure virtual network gateway. App Service gateway-required VNet integration relies on it too.
- AD DS
Short for Active Directory Domain Services, the domain controller-based Windows directory run on-premises. Microsoft Entra Domain Services offers a managed counterpart.
- MFA
Multifactor authentication: asking for another factor on top of a password at sign-in, usually required by a Conditional Access grant control.
Related terms
- MSCHAPv2
When the NPS extension is used and the RADIUS client talks to NPS with this challenge-response protocol, MFA is limited to push notifications and phone calls. Code-based (TOTP) methods require PAP.
- PAP
Password Authentication Protocol, a RADIUS password protocol which, when used between NPS and the RADIUS client, lets the NPS extension support all Microsoft Entra MFA methods, TOTP codes from OATH tokens or Authenticator included.