What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
“Microsoft Network Access Control” is an umbrella term, not the name of one current Microsoft product. For network access today, the relevant pieces are Network Policy Server (NPS), Microsoft’s Windows Server RADIUS service, and Microsoft Intune integrations with third-party NAC products. Network Access Protection (NAP) is a separate, legacy Windows platform that is unavailable starting with Windows 10.
What does Microsoft Network Access Control mean?
The phrase can refer to three different things, which should not be treated as interchangeable:
- NPS: A Windows Server role that provides RADIUS authentication, authorization, and accounting for supported network connections.
- Intune-integrated NAC: An arrangement in which a third-party NAC product checks Intune enrollment or compliance information and makes its own network-access decision.
- NAP: Microsoft’s former endpoint health-validation and network-restriction platform. Microsoft states that the NAP platform is not available starting with Windows 10.
NPS and Intune-integrated NAC can be part of a current access-control design, but they solve different parts of the problem. NPS evaluates RADIUS requests against Windows Server policies. In an Intune integration, Intune supplies device state and the partner NAC product enforces access according to its configuration.
How Windows Server NPS and RADIUS work
NPS is Microsoft’s RADIUS server and proxy implementation. In a typical deployment, a network access server—such as a wireless access point, VPN server, or 802.1X-capable switch—sends an authentication request to NPS. NPS evaluates the request using network policies and account properties, then returns an authorization result. The network access server applies that result to the connection.
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
In Microsoft’s terminology, the RADIUS clients are those network access servers or RADIUS proxies—not users’ laptops, phones, or other endpoint computers. For wired or wireless 802.1X access, the relevant network equipment must support 802.1X. EAP or PEAP deployments also require compatible support on the network devices. See Microsoft’s NPS overview and planning guidance and NPS network policy documentation.
Authentication choices depend on the environment
Microsoft documents both password-based and certificate-based approaches; the methods available depend in part on the network access server. Two examples illustrate the operational trade-off:
- EAP-TLS: Uses client and server certificates. It requires an organizational public key infrastructure (PKI), which Microsoft notes can be complex to deploy.
- PEAP-MS-CHAP v2: Uses a server certificate with password-based user credentials and does not require deploying a PKI.
Neither method is universally right for every organization. Choose based on security requirements, certificate and identity infrastructure, supported network equipment, and the effort your team can sustain.
Rank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
Network policies are ordered rules
NPS evaluates network policies in order. When the request matches a policy’s conditions, NPS applies that policy’s settings, subject to its constraints. A request that fails a constraint is rejected; NPS does not continue to later network policies. This means policy order and the distinction between conditions and constraints matter when configuring access or diagnosing an unexpected rejection.
Practical NPS deployment checklist
- Define the Windows Server domain context and the identities or groups that should be eligible for access.
- Record each RADIUS client’s IP address and any required vendor-specific attributes.
- Configure the same shared secret on NPS and the corresponding network access server.
- Choose authentication methods supported by the network equipment and appropriate to the organization’s certificate and credential infrastructure.
- Plan for redundancy. Microsoft recommends at least two NPS servers for fault tolerance in RADIUS-based authentication and accounting.
- Review network-policy order and constraints when testing both allowed and denied requests.
How Intune works with a third-party NAC product
In an Intune-integrated design, Intune is the source of enrollment and compliance information; the partner NAC product is the network enforcement point. Microsoft’s documented flow involves registering the partner with Microsoft Entra ID, granting the required delegated permissions to the Intune NAC API, and configuring partner-specific settings and authentication. When a user attempts to connect to Wi-Fi or VPN, the NAC solution can query device state and use the result in its access decision. Depending on the partner’s configuration, a device that is not enrolled or is noncompliant can be sent to enrollment or remediation, while a compliant device can be granted access.
Microsoft says its compliance retrieval service replaced the previous Intune NAC service and that the service was released in July 2021. Its documentation lists integrations including Cisco ISE 3.1 and later; Aruba ClearPass with Microsoft Intune Extension v6 and later; Forescout eyeExtend Microsoft Module v1.0.1 and later; Portnox Cloud; Fortinet FortiNAC 9.4.x and FortiNAC-F 7.x and later; and products from Extreme, Citrix, F5, and Ivanti. This is a documentation snapshot, not a guarantee of continued support for every listed product version. Check current Microsoft and vendor documentation for the exact product, version, and configuration before deployment. The integration is documented at Microsoft Intune NAC partner compliance retrieval.
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
Device identification and certificate configuration
For the compliance retrieval service, Microsoft recommends certificate-based authentication wherever possible. In the documented approach, the Intune device ID is included as a certificate subject alternative name. If certificate authentication cannot be used, the service supports lookup by MAC address. The appropriate identifier and certificate setup depend on the partner integration; a NAC product upgrade may also require configuration changes.
Query throttling for broad compliance requests
Microsoft warns that broad, unfiltered requests for all noncompliant devices may be throttled. It advises NAC solutions to submit such requests no more than once every four hours; more frequent requests receive HTTP 503. This is a service behavior for that query pattern, not a universal limit on every NAC query. Follow the Microsoft and partner guidance for the integration you operate.
NPS and Intune-integrated NAC compared
| Area | Windows Server NPS/RADIUS | Intune-integrated third-party NAC |
|---|---|---|
| Decision point | NPS evaluates RADIUS requests; a network access server applies the returned result. | The partner NAC product evaluates its configured access rules and enforces the network decision. |
| Decision inputs | Credentials or certificates, account properties, and ordered NPS network policies. | Intune enrollment and compliance state, along with the partner product’s own configuration. |
| Network paths | RADIUS-based wireless, authenticating-switch, dial-up, and VPN connections; 802.1X requires compatible access equipment. | Wi-Fi or VPN are examples in Microsoft’s integration flow; available paths depend on the partner product and deployment. |
| Prerequisites | Windows Server, supported RADIUS clients, matching shared secrets, compatible authentication methods, and PKI if using certificate methods such as EAP-TLS. | Intune enrollment, partner registration and API permissions, partner-supported versions, and configured device identification and authentication. |
| Operational focus | Policy ordering, constraint behavior, network-device compatibility, shared secrets, and NPS redundancy. | Partner-version support, certificate or MAC-based device identification, and compliance-query behavior. |
These approaches are not necessarily mutually exclusive: an organization may use RADIUS and NPS in its network architecture while also using a partner product that consumes Intune device state. The documentation describes different responsibilities, not a universal product ranking.
Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
What happened to Windows Network Access Protection?
Network Access Protection (NAP) was a Windows platform for validating endpoint health, restricting network access, directing devices toward remediation, and checking compliance over time. It is historical rather than a current Windows endpoint feature: Microsoft’s legacy documentation says, “The NAP platform is not available starting with Windows 10.” The same overview documents client support for Windows XP SP3, Windows Vista, and Windows Server 2008. Do not use those legacy client references as current Windows 10 or Windows 11 deployment guidance. See Microsoft’s legacy NAP overview.
Which approach should you investigate?
- Start with NPS if you need a Windows Server RADIUS service for compatible Wi-Fi, wired 802.1X, VPN, or other RADIUS-based access devices and want to apply Windows Server network policies.
- Look at an Intune NAC integration if your access decision needs to use Intune enrollment or compliance state and your NAC vendor supports the required Microsoft integration for your product version.
- Do not select NAP for a new Windows 10 or Windows 11 design. Its platform is unavailable starting with Windows 10.
For wired 802.1X, a compatible managed switch can be one part of an NPS deployment, but a switch alone does not provide NPS or a complete NAC system. Verify the selected equipment’s 802.1X and RADIUS capabilities against the intended design.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems

