Switching from Azure Point-To-Site VPN Certificate Authentication to Entra ID

Scion 60 Reputation points
2025-03-22T07:01:47.44+00:00

Hi,

We are currently using Azure Point-To-Site VPN with certificate authentication and are considering switching to Entra ID for user authentication. Could you please confirm if this transition is straightforward and provide relevant documentation if possible? Are there any potential challenges or considerations we should be aware of during this process?

Thank you for any help in advance!
Scion

Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
1,718 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Sai Prasanna Sinde 5,240 Reputation points Microsoft External Staff
    2025-03-24T05:11:33.54+00:00

    Hi @Scion

    You'll need to update the VPN gateway configuration to use Entra ID authentication instead of certificate authentication.

    This involves specifying the Entra ID tenant ID, application ID, and issuer URL.

    Refer: Configure P2S VPN Gateway for Microsoft Entra ID authentication.

    You need to download the Azure VPN Client and configure it to use Entra ID authentication and the configuration files for the VPN client are downloaded from the virtual network gateway.

    Refer: Configure Azure VPN Client – Microsoft Entra ID authentication – Windows.

    Make sure that users have the necessary permissions in Entra ID to connect to the VPN or else you can use Entra ID groups to manage user access.

    Refer: Group types, membership types, and access management.

    NOTE: Make sure that you need to select the tunnel type as "Open VPN (SSL)" for configuring Microsoft Entra ID authentication in VPN P2S.


    Kindly click 'Accept answer' if the above response is helpful or let us know if the above response is helpful in the comments below.

    If you still have questions, please let us know what is needed in the comments so the question can be answered.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.