VPN profiles in Configuration Manager

Applies to: Configuration Manager (current branch)


Starting in version 2203, this company resource access feature is no longer supported. For more information, see Frequently asked questions about resource access deprecation.

To deploy VPN settings to users in your organization, use VPN profiles in Configuration Manager. By deploying these settings, you minimize the end-user effort required to connect to resources on the company network.

For example, you want to configure all Windows 10 devices with the settings required to connect to a file share on the internal network. Create a VPN profile with the settings necessary to connect to the internal network. Then deploy this profile to all users that have devices running Windows 10. These users see the VPN connection in the list of available networks and can connect with little effort.

When you create a VPN profile, you can include a wide range of security settings. These settings include certificates for server validation and client authentication that you provision with Configuration Manager certificate profiles. For more information, see Certificate profiles.


Configuration Manager doesn't enable this optional feature by default. You must enable this feature before using it. For more information, see Enable optional features from updates.

Supported platforms

The following table describes the VPN profiles you can configure for various device platforms.

Connection type Windows 8.1 Windows RT Windows RT 8.1 Windows 10
Pulse Secure Yes No Yes Yes
F5 Edge Client Yes No Yes Yes
Dell SonicWALL Mobile Connect Yes No Yes Yes
Check Point Mobile VPN Yes No Yes Yes
Microsoft SSL (SSTP) Yes Yes Yes No
Microsoft Automatic Yes Yes Yes No
IKEv2 Yes Yes Yes No
PPTP Yes Yes Yes No
L2TP Yes Yes Yes No

Next step

See also