Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
You can assign users connecting to your Point-to-site (P2S) VPN gateway IP addresses from specific address pools based on their identity or authentication credentials by creating Policy Groups (User Groups). This article helps you configure Policy Groups, Group Members, and prioritize groups using Azure CLI. For more information about working with Policy Groups and Group Members for P2S connections, including considerations and limitations, see About User Groups.
Prerequisites
This article assumes you have a VPN Gateway P2S configuration. If you haven't already set up a P2S VPN gateway, see the following articles:
- Configure a P2S VPN gateway with certificate authentication:
- For Portal see, Configure server settings for P2S VPN Gateway certificate authentication
- For PowerShell see, P2S VPN Gateway certificate authentication - PowerShell
- Steps to configure a P2S VPN Gateway with Microsoft Entra ID authentication see, P2S VPN Gateway for Microsoft Entra ID authentication
- To configure an Azure VPN client, see the VPN Client Configuration Table.
Use the Bash environment in Azure Cloud Shell. For more information, see Get started with Azure Cloud Shell.
If you prefer to run CLI reference commands locally, install the Azure CLI. If you're running on Windows or macOS, consider running Azure CLI in a Docker container. For more information, see How to run the Azure CLI in a Docker container.
If you're using a local installation, sign in to the Azure CLI by using the az login command. To finish the authentication process, follow the steps displayed in your terminal. For other sign-in options, see Authenticate to Azure using Azure CLI.
When you're prompted, install the Azure CLI extension on first use. For more information about extensions, see Use and manage extensions with the Azure CLI.
Run az version to find the version and dependent libraries that are installed. To upgrade to the latest version, run az upgrade.
Workflow
This article uses the following workflow to help you set up user groups and IP address pools for your P2S VPN Gateway connection.
- Consider configuration requirements.
- Choose an authentication mechanism.
- Create a User Group.
- Configure gateway settings.
Consider configuration requirements
This section lists configuration requirements and limitations for user groups and IP address pools.
Maximum Groups: A single P2S VPN gateway can reference up to 90 groups.
Maximum Members: The total number of policy/group members across all groups assigned to a gateway is 390.
Multiple Assignments: If a group is assigned to multiple connection configurations on the same gateway, it and its members are counted multiple times. Example: A policy group with 10 members assigned to three VPN connection configurations counts as three groups with 30 members, not one group with 10 members.
Concurrent Users: The total number of concurrent users is determined by the gateway’s scale unit and the number of IP addresses allocated to each user group. It is not determined by the number of policy/group members associated with the gateway.
Once a group has been created as part of a VPN server configuration, the name and default setting of a group can't be modified.
Group names should be distinct.
Groups that have lower numerical priority are processed prior to groups with higher numerical priority. If a connecting user is a member of multiple groups, the gateway considers them to be a member of the group with lower numerical priority for purposes of assigning IP addresses.
Groups that are being used by existing point-to-site VPN gateways can't be deleted.
You can reorder the priorities of your groups by clicking on the up-down arrow buttons corresponding to that group.
- Address pools can't overlap with address pools used in other connection configurations (same or different gateways).
- Address pools also can't overlap with virtual network address spaces, virtual hub address spaces, or on-premises addresses.
- Address pools can't be smaller than /24. For example, you can't assign a range of /25 or /26.
Choose authentication mechanism
The following sections list available authentication mechanisms that you can use when creating user groups.
Microsoft Entra groups
To create and manage Microsoft Entra groups, see Manage Microsoft Entra groups and group membership.
Specify the Microsoft Entra user group object ID (not the group name) as part of the point-to-site configuration.
You can assign Microsoft Entra users to be part of multiple Active Directory groups, and VPN Gateway considers users to be part of the VPN user or policy. If a user belongs to multiple groups, the group that has the lowest numerical priority is selected in the point-to-site connection.
RADIUS - NPS vendor-specific attributes
For Network Policy Server (NPS) vendor-specific attributes configuration information, see RADIUS - configure NPS for vendor-specific attributes.
Certificates
To generate self-signed certificates, see Generate and export certificates for point-to-site using PowerShell. To generate a certificate with a specific Common Name, change the Subject parameter to the appropriate value (example, xx@domain.com) when running the New-SelfSignedCertificate PowerShell command. For example, you can generate certificates with the following Subject:
| Digital certificate field | Value | Description |
|---|---|---|
| Subject | CN= cert@marketing.contoso.com | digital certificate for Marketing department |
| Subject | CN= cert@sale.contoso.com | digital certificate for Sale department |
The multiple address pool feature with digital certificate authentication applies to a specific user group based on the Subject field. The selection criteria don't work with Subject Alternative Name (SAN) certificates.
If you want to specify a SAN in their certificates, it must be the same as the Subject for the multipool feature to function correctly. Discrepancy between the Subject and SAN results in issues.
Create user groups
1. Declare your variables
rg="p2s-multipool"
location="eastus"
vnetName="VNet1"
vNetAddressPrefix="10.1.0.0/16"
gatewaySubnetPrefix="10.1.0.0/24"
gatewayName="gw"
# Name of the first public IP address of the gateway
gwpip="${gatewayName}-pip"
# Local folder that holds the exported root certificate (P2SRoot.cer).
# The gateway-create command references the .cer file by this path.
pathFiles="$(pwd)"
certPath="$pathFiles/cert"
2. Connect to your account and create the virtual network
Open your Bash console and connect to your account. For more information, see Manage Azure resources by using Azure CLI. Use the following sample to help you connect:
az account set --subscription <YourSubscriptionName>
az account show
Create the resource group, virtual network, gateway subnet, and the public IP address for the gateway.
# create a Resource Group
az group create --name "$rg" --location "$location"
# create an Azure VNet
az network vnet create \
--name "$vnetName" \
--resource-group "$rg" \
--location "$location" \
--address-prefixes "$vNetAddressPrefix"
# create the GatewaySubnet
az network vnet subnet create \
--name "GatewaySubnet" \
--vnet-name "$vnetName" \
--resource-group "$rg" \
--address-prefixes "$gatewaySubnetPrefix"
# create the first public IP of the VPN Gateway
az network public-ip create \
--name "$gwpip" \
--resource-group "$rg" \
--location "$location" \
--allocation-method Static \
--sku Standard \
--tier Regional \
--zone 1 2 3
3. Plan your user groups
In this scenario, consider four user groups: two user groups that use digital certificate authentication and two user groups that use Microsoft Entra ID authentication.
Two groups use client certificates with common names.
yourServiceName@marketing.contoso.comyourServiceName@sale.contoso.com
Two groups created in Microsoft Entra ID. The following object IDs are examples; replace them with your actual Microsoft Entra group object IDs.
- Engineering group
aaaaaaaa-0000-1111-2222-bbbbbbbbbbbb - Finance
bbbbbbbb-1111-2222-3333-cccccccccccc
- Engineering group
4. Create the VPN gateway and add P2S configuration
The following configuration sets up the VPN gateway to use a client address pool and authentication options:
- Certificate-based authentication: Certificate
- Microsoft Entra ID: AAD
For more information about P2S Microsoft Entra ID authentication values, see Configure P2S VPN Gateway for Microsoft Entra ID authentication.
Export the public data of your root certificate in .cer format and save it as P2SRoot.cer in the cert folder referenced by the $certPath variable. The .cer file holds only the public certificate, not the private key. Reference this file by its full path in the --root-cert-data parameter of the following command.
Next, create the virtual network gateway. In the following command, replace the following values:
- The tenant ID in
--aad-tenantand--aad-issuer(the example usesaaaabbbb-0000-cccc-1111-dddd2222eeee) with your Microsoft Entra tenant ID. - --aad-audience with the corresponding value for the Microsoft-registered Azure VPN Client App ID. You can also use custom audience in this field.
- 192.168.0.0/24 with the address pool to connect VPN clients not belonging to the multiple address pool configuration.
# Create the VPN Gateway with VpnGw2AZ SKU.
# $certPath/P2SRoot.cer is the local root certificate file to upload to the gateway.
# The .cer file holds only the public certificate, not the private key.
az network vnet-gateway create \
--name "$gatewayName" \
--resource-group "$rg" \
--location "$location" \
--vnet "$vnetName" \
--gateway-type Vpn \
--vpn-type RouteBased \
--sku VpnGw2AZ \
--public-ip-addresses "$gwpip" \
--address-prefixes "192.168.0.0/24" \
--client-protocol IkeV2 OpenVPN \
--vpn-auth-type Certificate AAD \
--root-cert-name "P2SRootcert" \
--root-cert-data "$certPath/P2SRoot.cer" \
--aad-tenant "https://login.microsoftonline.com/aaaabbbb-0000-cccc-1111-dddd2222eeee" \
--aad-issuer "https://sts.windows.net/aaaabbbb-0000-cccc-1111-dddd2222eeee/" \
--aad-audience "c632b3df-fb67-4d84-bdcf-b95ad541b5c8"
It can take about 45 minutes or more to create the VPN gateway.
5. Verify the VPN gateway
# shows the gateway configuration, including the P2S client address pool and the root certificate.
az network vnet-gateway show \
--name "$gatewayName" \
--resource-group "$rg"
6. Create policy groups and members
Using Azure CLI, define each policy group along with its members as a JSON object. Configure four members, one for each group:
member1andmember2use digital certificate authentication (authentication type: CertificateGroupId).member3andmember4use Microsoft Entra ID authentication (authentication type: AADGroupId).- The example object IDs
aaaaaaaa-0000-1111-2222-bbbbbbbbbbbbandbbbbbbbb-1111-2222-3333-ccccccccccccrepresent two different group IDs in your Microsoft Entra ID tenant. Replace them with your actual group object IDs.
- The example object IDs
| Member Name | Authentication Type | Attribute Value |
|---|---|---|
| member1 | CertificateGroupId | marketing.contoso.com |
| member2 | CertificateGroupId | sale.contoso.com |
| member3 | AADGroupId | aaaaaaaa-0000-1111-2222-bbbbbbbbbbbb |
| member4 | AADGroupId | bbbbbbbb-1111-2222-3333-cccccccccccc |
Create the four policy groups with the default policy and priority described in the following table:
| Policy group name | Default policy | Priority |
|---|---|---|
| policyGroup1 | true | 0 |
| policyGroup2 | false | 1 |
| policyGroup3 | false | 2 |
| policyGroup4 | false | 3 |
# policyGroup1 - default group, priority 0, member1 (CertificateGroupId)
policyGroup1='{
"name": "policyGroup1",
"properties": {
"isDefault": true,
"priority": 0,
"policyMembers": [
{
"name": "member1",
"attributeType": "CertificateGroupId",
"attributeValue": "marketing.contoso.com"
}
]
}
}'
# policyGroup2 - priority 1, member2 (CertificateGroupId)
policyGroup2='{
"name": "policyGroup2",
"properties": {
"isDefault": false,
"priority": 1,
"policyMembers": [
{
"name": "member2",
"attributeType": "CertificateGroupId",
"attributeValue": "sale.contoso.com"
}
]
}
}'
# policyGroup3 - priority 2, member3 (AADGroupId)
policyGroup3='{
"name": "policyGroup3",
"properties": {
"isDefault": false,
"priority": 2,
"policyMembers": [
{
"name": "member3",
"attributeType": "AADGroupId",
"attributeValue": "aaaaaaaa-0000-1111-2222-bbbbbbbbbbbb"
}
]
}
}'
# policyGroup4 - priority 3, member4 (AADGroupId)
policyGroup4='{
"name": "policyGroup4",
"properties": {
"isDefault": false,
"priority": 3,
"policyMembers": [
{
"name": "member4",
"attributeType": "AADGroupId",
"attributeValue": "bbbbbbbb-1111-2222-3333-cccccccccccc"
}
]
}
}'
Note
The Microsoft Entra group object IDs shown (for example, aaaaaaaa-0000-1111-2222-bbbbbbbbbbbb) are sample values. Replace them with the actual object IDs from your Microsoft Entra ID tenant.
7. Add policy groups to the VPN gateway
The following configuration adds the four gateway policy groups to the VPN gateway. These groups authorize connections by using digital certificates that specify a value in the Common Name (CN) field and Microsoft Entra ID groups that specify the group Object IDs:
- policyGroup1: marketing.contoso.com, member1
- policyGroup2: sale.contoso.com, member2
- policyGroup3:
aaaaaaaa-0000-1111-2222-bbbbbbbbbbbb, member3 - policyGroup4:
bbbbbbbb-1111-2222-3333-cccccccccccc, member4
# Repeat the --add flag, one per policy group.
az network vnet-gateway update \
--name "$gatewayName" \
--resource-group "$rg" \
--add virtualNetworkGatewayPolicyGroups "$policyGroup1" \
--add virtualNetworkGatewayPolicyGroups "$policyGroup2" \
--add virtualNetworkGatewayPolicyGroups "$policyGroup3" \
--add virtualNetworkGatewayPolicyGroups "$policyGroup4"
Show the list of policy group names:
# List the current policy groups in order.
# index order: the first entry is index 0, the second is index 1, and so on.
az network vnet-gateway show \
--name "$gatewayName" \
--resource-group "$rg" \
--query "virtualNetworkGatewayPolicyGroups[].name" \
--output tsv
Visualize all the properties of a specific policy group:
# Show the properties of a specific group, for example policyGroup2:
az network vnet-gateway show \
--name "$gatewayName" \
--resource-group "$rg" \
--query "virtualNetworkGatewayPolicyGroups[?name=='policyGroup2']" \
--output json
8. Create VPN client connection configurations
The VPN configuration defines four distinct address pools, each linked to a specific policy group.
| VPN client Configuration Name | Address Pool | PolicyGroup |
|---|---|---|
| config1 | 192.168.1.0/24 | policyGroup1: marketing.contoso.com |
| config2 | 192.168.2.0/24 | policyGroup2: sale.contoso.com |
| config3 | 192.168.3.0/24 | policyGroup3: Engineering aaaaaaaa-0000-1111-2222-bbbbbbbbbbbb |
| config4 | 192.168.4.0/24 | policyGroup4: Finance bbbbbbbb-1111-2222-3333-cccccccccccc |
Note
The example pools (192.168.1.0/24, 192.168.2.0/24, and so on) use a documentation-safe range. Replace them with real address ranges for your environment. Each pool must be at least a /24, can't overlap with the other pools or with the default gateway address pool, and can't overlap with your virtual network, virtual hub, or on-premises address spaces.
First, retrieve the ID of each policy group:
# Create per-policy-group P2S client connection configurations with dedicated pools.
policyGroup1Id=$(az network vnet-gateway show -g "$rg" -n "$gatewayName" --query "virtualNetworkGatewayPolicyGroups[?name=='policyGroup1'].id | [0]" -o tsv)
policyGroup2Id=$(az network vnet-gateway show -g "$rg" -n "$gatewayName" --query "virtualNetworkGatewayPolicyGroups[?name=='policyGroup2'].id | [0]" -o tsv)
policyGroup3Id=$(az network vnet-gateway show -g "$rg" -n "$gatewayName" --query "virtualNetworkGatewayPolicyGroups[?name=='policyGroup3'].id | [0]" -o tsv)
policyGroup4Id=$(az network vnet-gateway show -g "$rg" -n "$gatewayName" --query "virtualNetworkGatewayPolicyGroups[?name=='policyGroup4'].id | [0]" -o tsv)
Next, load the VPN client configuration in JSON format into the variables vngClientConnConfig1, vngClientConnConfig2, vngClientConnConfig3, and vngClientConnConfig4:
read -r -d '' vngClientConnConfig1 <<EOF
{
"name": "config1",
"properties": {
"virtualNetworkGatewayPolicyGroups": [
{ "id": "$policyGroup1Id" }
],
"vpnClientAddressPool": {
"addressPrefixes": ["192.168.1.0/24"]
}
}
}
EOF
read -r -d '' vngClientConnConfig2 <<EOF
{
"name": "config2",
"properties": {
"virtualNetworkGatewayPolicyGroups": [
{ "id": "$policyGroup2Id" }
],
"vpnClientAddressPool": {
"addressPrefixes": ["192.168.2.0/24"]
}
}
}
EOF
read -r -d '' vngClientConnConfig3 <<EOF
{
"name": "config3",
"properties": {
"virtualNetworkGatewayPolicyGroups": [
{ "id": "$policyGroup3Id" }
],
"vpnClientAddressPool": {
"addressPrefixes": ["192.168.3.0/24"]
}
}
}
EOF
read -r -d '' vngClientConnConfig4 <<EOF
{
"name": "config4",
"properties": {
"virtualNetworkGatewayPolicyGroups": [
{ "id": "$policyGroup4Id" }
],
"vpnClientAddressPool": {
"addressPrefixes": ["192.168.4.0/24"]
}
}
}
EOF
9. Apply configurations to the VPN gateway
az network vnet-gateway update \
--name "$gatewayName" \
--resource-group "$rg" \
--add vpnClientConfiguration.vngClientConnectionConfigurations "$vngClientConnConfig1" \
--add vpnClientConfiguration.vngClientConnectionConfigurations "$vngClientConnConfig2" \
--add vpnClientConfiguration.vngClientConnectionConfigurations "$vngClientConnConfig3" \
--add vpnClientConfiguration.vngClientConnectionConfigurations "$vngClientConnConfig4"
List the VPN client connection configurations in index order.
# list of vpn client connection configs (index order)
az network vnet-gateway show \
--name "$gatewayName" \
--resource-group "$rg" \
--query "vpnClientConfiguration.vngClientConnectionConfigurations[].name" -o tsv
At the end of the multiple address pool setting, the configuration can be represented by the following logical structure:
| Policy group name | Default policy | Priority | Authentication type | Group configuration value | VPN Client address pool |
|---|---|---|---|---|---|
| policyGroup1 | true | 0 | CertificateGroupId | marketing.contoso.com | 192.168.1.0/24 |
| policyGroup2 | false | 1 | CertificateGroupId | sale.contoso.com | 192.168.2.0/24 |
| policyGroup3 | false | 2 | AADGroupId | aaaaaaaa-0000-1111-2222-bbbbbbbbbbbb |
192.168.3.0/24 |
| policyGroup4 | false | 3 | AADGroupId | bbbbbbbb-1111-2222-3333-cccccccccccc |
192.168.4.0/24 |
View address pool configurations
Use the following commands to view the address pools associated with your policy groups.
# Show the address pool associated with a policy group
az network vnet-gateway show \
--name "$gatewayName" \
--resource-group "$rg" \
--query "vpnClientConfiguration.vngClientConnectionConfigurations[?name=='config1'].vpnClientAddressPool.addressPrefixes[]" \
--output tsv
# Show the config name of the address pool configuration and the associated address pool(s)
az network vnet-gateway show \
--name "$gatewayName" \
--resource-group "$rg" \
--query "vpnClientConfiguration.vngClientConnectionConfigurations[].{config:name,addressPools:join(', ', vpnClientAddressPool.addressPrefixes)}" \
--output table
You can also show the policy group name, config name, and associated address pool together:
# show policy group name, config name, and associated address pool(s)
az network vnet-gateway show -n "$gatewayName" -g "$rg" -o json |
jq -r '.vpnClientConfiguration.vngClientConnectionConfigurations[]? |
[(.virtualNetworkGatewayPolicyGroups[0].id // "" | split("/")[-1]),
(.name // ""),
(.vpnClientAddressPool.addressPrefixes // [] | join(", "))] | @tsv' |
column -t -s $'\t'
Remove address pool configurations
To remove a specific address pool configuration, use --remove in Azure CLI to remove a list element by its zero-based index. Check the ordered list first, then remove the matching position.
# Remove an address pool configuration
# Az CLI removes a list element by its zero-based INDEX with --remove.
# You check the ordered list first, then remove the matching position (index 3 = the 4th group, policyGroup4).
az network vnet-gateway update \
--name "$gatewayName" \
--resource-group "$rg" \
--remove vpnClientConfiguration.vngClientConnectionConfigurations 3
# Remove the policyGroup4
az network vnet-gateway update \
--name "$gatewayName" \
--resource-group "$rg" \
--remove virtualNetworkGatewayPolicyGroups 3
To remove all policy groups and address pool configurations:
# Removing all policy groups and address pools
az network vnet-gateway update \
--name "$gatewayName" \
--resource-group "$rg" \
--set vpnClientConfiguration.vngClientConnectionConfigurations=[] \
--set virtualNetworkGatewayPolicyGroups=[]
If things go wrong
The following are some common issues that you might encounter when configuring policy groups and IP address pools for P2S connections, along with troubleshooting steps to help you resolve them.
Verify packets have the right attributes? Wireshark or another packet capture can be run in NPS mode and decrypt packets using shared key. You can validate packets are being sent from your RADIUS server to the point-to-site VPN gateway with the right RADIUS VSA configured.
Are users getting wrong IP assigned? Set up and check NPS Event logging for authentication whether or not users are matching policies.
Having issues with address pools? Every address pool is specified on the gateway. Address pools are split into two address pools and assigned to each active-active instance in a point-to-site VPN gateway pair. These split addresses should show up in the effective route table. For example, if you specify 10.0.0.0/24, you should see two "/25" routes in the effective route table. If this isn't the case, try changing the address pools defined on the gateway.
P2S client not able to receive routes? Make sure all point-to-site VPN connection configurations are associated to the defaultRouteTable and propagate to the same set of route tables. This should be configured automatically if you're using portal, but if you're using REST, PowerShell or CLI, make sure all propagations and associations are set appropriately.
Not able to enable Multipool using Azure VPN client? If you're using the Azure VPN client, make sure the Azure VPN client installed on user devices is the latest version. You need to download the client again to enable this feature.
All users getting assigned to Default group? If you're using Microsoft Entra authentication, make sure the tenant URL input in the server configuration
(https://login.microsoftonline.com/<tenant ID>)doesn't end in a\. If the URL is input to end with\, the gateway won't be able to properly process Microsoft Entra user groups, and all users are assigned to the default group. To remediate, modify the server configuration to remove the trailing\and modify the address pools configured on the gateway to apply the changes to the gateway. This is a known issue.Trying to invite external users to use Multipool feature? If you're using Microsoft Entra authentication and you plan to invite users who are external (users who aren't part of the Microsoft Entra domain configured on the VPN gateway) to connect to the VPN gateway, make sure that the user type of the external user is Member and not Guest. Also, make sure that the "Name" of the user is set to the user's email address. If the user type and name of the connecting user isn't set correctly, or you can't set an external member to be a "Member" of your Microsoft Entra domain, the connecting user is assigned to the default group and assigned an IP from the default IP address pool.