VPN
The VPN policy configuration distributes VPN profiles to managed Windows devices centrally. Besides the connection itself, the configuration covers authentication, name resolution, split tunnelling and proxy settings.
The profile name is the unique identifier of a VPN profile on the device. It has to differ from every other VPN configuration within the same policy version.
Connection
- Profile name
- VPN type
- Server names
- Connect automatically
- Remember credentials
- Use Windows logon credentials
Authentication
- Authentication type
- Machine certificate
- Secured password (EAP)
- Identity Certificate
- Certificate type
- Pre Shared Key
- Use strong cipher keys
EAP settings
With the Protected password (EAP) authentication type, the following fields are additionally available:
- Extensible Authentication Protocol (EAP)
- Inner authentication
- Inner authentication type
- Trusted Certificates
- Trusted Server Names
- Enable fast reauthentication
- Enable usage of Realms
- Specify a realm
- Anonymous username
- Don’t reveal real identity to the server when pseudonym identity is available
- Ignore mismatched network names
- Notify user when server identity cannot be verified
- Don’t prompt user if unable to authorise the server
Name resolution and routes
- Name Resolution Policy table (NRPT) rules
- Name Resolution Policy table (NRPT) rules define how the DNS resolves names when connected to the VPN. Each row in the table specifies a domain and the DNS suffixes or web proxy server to use to resolve that domain.
- Automatically connect to the VPN when the device connects to this domain
- Keep this rule active even when the VPN is not connected.
- Specify DNS suffixes to add to the DNS search list to properly route short names. The first in the list is also used as the primary connection specific DNS suffix for the VPN Interface.
- Split tunneling routes for this VPN connection
- The IPv4/v6 CIDR address, which will be used to determine the destination prefix to send via the VPN Interface.
Proxy
- Proxy configuration
- Proxy type
- Automatic
- Manual
- Proxy server
- Proxy server port
- Proxy configuration URL
App triggers
- Apps added here will automatically connect to the VPN when started. For desktop apps, add the file path to the app. For universal (UWP) apps, add the package family name
- Restrict VPN connection to these apps
Related topics
- Certificates → — provide identity and trust certificates.
- Wi-Fi → — network profiles for Windows devices.