As you have mentioned that you have used Point-to-Site connection . The P2S VPN connection to the AAD domain services Virtual network may still be connected for the local admin account's session but the same would not be available for other user logging on to the same server. It is available separately for each user so every user would have to connect the VPN again . I am not sure of the VPN client you are using but if you are using Azure P2S VPN client on a windows 10 machine to connect then you may be able to configure Always on VPN device tunnel. This is a native feature of Windows 10. Please check the linked article. Its a long read.
Since you are running Azure AD domain services so , I am assuming that you have a requirement to deploy and run some applications which require legacy protocol auth (Kerberos , NTLM etc.) and you may be running them in a different cloud. For critical production application workloads , I would always recommend to use site-to-site VPN for simplicity and continuous availability .
Hope the information helps. In case you still have any further queries , please do let us know and we will be happy to help you further.
Thank you.
-----------------------------------------------------------------------------------------------------------
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.