4.1 Security Considerations for Implementers
The Group Policy: NAP Extension sets the NAP enforcement policy on the client computer. This policy consists of HRA URLs and HRA connection transport and certificate security settings, as well as enforcement enabling. These configurations can also be set by the user through the NAP configuration UI. Therefore, it is extremely important that an implementation provide a means of protecting the integrity of the NAP policy against tampering, especially during its transfer from server to client. Ideally, this implementation-specific security method is provided as part of the transport for the Group Policy: Core Protocol.