Is it possible in Intune or Entra to audit if aovpn users successfully received a certifiate from Entra CA certificate authority.

James Gledson 160 Reputation points
2024-04-24T16:28:41.6+00:00

We have set up a Always On VPN user tunnel policy in Intune. The users device goes to the Entra Conditional Access function and if it passes, they get a 1 hour certifiate from the MS VPN root CA, put into their User Cert folder. Is there a way to audtit on Intune/Entra when this is not successfull or the cert has failed to be issued?

Thanks in advance.

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,365 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,569 questions
0 comments No comments
{count} votes

Accepted answer
  1. ZhoumingDuan-MSFT 8,065 Reputation points Microsoft Vendor
    2024-04-25T05:23:24.3966667+00:00

    @James Gledson, Thanks for posting in Q&A.

    Based on my research, when you deploy Always On VPN profile to device via Intune, the profile status in Intune will show success or failure, but there is not feature in Intune that can audit it.

    You can try to audit on targeted devices when this is not successful, or the cert has failed to be issued.

    https://directaccess.richardhicks.com/2022/08/08/always-on-vpn-nps-auditing-and-logging/

    Non-official, just for reference.

    Hope it will help.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


0 additional answers

Sort by: Most helpful