Provision new device with GlobalProtect VPN Client and User certificate

Andrew Stevenson (IT) 0 Reputation points
2023-04-06T10:51:05.8633333+00:00

Hi folks,

This is probably a straightforward one, but due to my limited knowledge around certificates, I'm a little stumped. We use GlobalProtect VPN Client, which authenticates the user using a combination of their username/password and the CA issued user cert. On-prem, there's no issue - A, because the users are able to directly connect to the DC and get/renew the cert (using auto-enrollment) and B, we have the VPN client to stop when on an internal network. We're looking to move toward Intune to provision devices for users - join domain, push apps, etc. - nothing too major. However I'm struggling to understand how the devices can join the domain, have the VPN client installed, and have a user login and the user cert be there waiting for them. Currently, the VPN doesn't join due to no user cert, and the domain join process not fully completing. There's no plan, or intention, to move to device based authentication at this time. Sorry for the open endedness of the query, but any help would be appreciated. Thanks.

Windows for business | Windows Client for IT Pros | User experience | Other
Microsoft Security | Intune | Other
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.