Ensure that your Microsoft Azure VPN Gateway is configured to use Azure Active Directory (Microsoft Entra ID) as the sole authentication type for point-to-site (P2S) connections. Azure VPN Gateway supports multiple authentication types for point-to-site configurations, including Azure certificate, RADIUS authentication, and Azure Active Directory. Configuring Azure Active Directory as the only authentication type ensures that all P2S connections are authenticated through Microsoft's centralized identity management system, preventing the concurrent use of static credentials or certificate-based authentication for VPN access.
Using Azure Active Directory (Microsoft Entra ID) as the exclusive authentication type for VPN Gateway point-to-site connections provides strong security through centralized identity management and eliminates risks associated with static credentials and certificate management. Certificate-based and RADIUS authentication methods rely on credentials that can be compromised, mismanaged, or shared without central oversight. Microsoft Entra ID enforces modern authentication controls including multi-factor authentication (MFA), conditional access policies, and integration with organizational user lifecycle management, enabling automatic access revocation when users leave the organization and providing comprehensive audit logs for all connection attempts.
Audit
To determine if your Microsoft Azure VPN Gateway is configured to use Azure Active Directory as the only authentication type for point-to-site connections, perform the following operations:
Remediation / Resolution
To configure your Microsoft Azure VPN Gateway to use Azure Active Directory (Microsoft Entra ID) as the only authentication type for point-to-site connections, perform the following operations:
Important: Changing the authentication type on an active VPN Gateway point-to-site configuration will disconnect all existing VPN clients. Ensure that affected users download and configure the updated Azure VPN Client profile after completing the remediation steps.References
- Azure Official Documentation
- About Azure VPN Gateway | Microsoft Learn
- Configure P2S VPN gateway for Microsoft Entra ID authentication: Microsoft-registered client - Azure VPN Gateway | Microsoft Learn
- Configure a P2S VPN - Microsoft Entra ID authentication - manually registered Azure VPN Client App ID - Azure VPN Gateway | Microsoft Learn
- Azure Command Line Interface (CLI) Documentation
- az account | Microsoft Learn
- az account | Microsoft Learn
- az resource | Microsoft Learn
- az network vnet-gateway | Microsoft Learn
- az network vnet-gateway | Microsoft Learn
- az network vnet-gateway aad | Microsoft Learn
- CIS Security Documentation
- CIS Microsoft Azure Benchmarks