Edit

Configure a VPN client for P2S Microsoft Entra ID authentication connections

This article helps you configure the Azure VPN Client to connect to a virtual network using a VPN Gateway point-to-site (P2S) VPN and Microsoft Entra ID authentication. Microsoft Entra ID authentication requires the OpenVPN® protocol and the Azure VPN Client. Select Windows or macOS for configuration steps, or Linux for retirement and migration guidance. For more information about point-to-site connections, see About point-to-site connections.

The steps in this article apply to Microsoft Entra ID authentication by using the Microsoft-registered Azure VPN Client app with associated App ID and Audience values. This article doesn't apply to the older, manually registered Azure VPN Client app for your tenant. For more information, see About point-to-site VPN - Microsoft Entra ID authentication.

Prerequisites

Configure your VPN gateway for point-to-site VPN connections that specify Microsoft Entra ID authentication. See Configure a P2S VPN gateway for Microsoft Entra ID authentication.

The Azure VPN Client supports Windows FIPS mode by using the KB4577063 hotfix.

While it's possible that the Azure VPN Client for Windows might work on other operating system versions, the Azure VPN Client for Windows is only supported on the following releases:

  • Supported Windows releases: Windows 11 on x64, x86, and ARM64 architectures.

Windows workflow

This article continues on from the Configure a P2S VPN gateway for Microsoft Entra ID authentication steps. This section helps you:

  1. Download and install the Azure VPN Client for Windows.
  2. Extract the VPN client profile configuration files.
  3. Update the profile configuration files with a custom audience value (if applicable).
  4. Import the client profile settings to the VPN client.
  5. Create a connection and connect to Azure.

Download the Azure VPN Client for Windows

The features and settings that are available for the Azure VPN Client are dependent on the version of the client that you're using. For Azure VPN Client version information, see Azure VPN Client versions.

  1. Download the latest version of the Azure VPN Client install files using one of the following links:

    • Install using Client Install files: https://aka.ms/azvpnclientdownload.

    • Install directly, when signed in on a client computer: Microsoft Store.

    • Install using the Windows Package Manager (WinGet). You can run the following command to install and learn more about the WinGet method in this document.

      winget install Microsoft.AzureVPNClient --source winget
      
  2. Install the Azure VPN Client to each computer.

  3. Verify that the Azure VPN Client has permission to run in the background. For steps, see Windows background apps.

  4. To verify the installed client version, open the Azure VPN Client. Go to the bottom of the client and select ... -> ? Help. In the right pane, you can see the client version number.

Extract Windows client profile configuration files

To configure your Azure VPN Client profile, you must first download the VPN client profile configuration package from the Azure P2S gateway. This package is specific to the configured VPN gateway and contains the necessary settings to configure the VPN client. If you used the P2S server configuration steps as mentioned in the Prerequisites section, you've already generated and downloaded the VPN client profile configuration package that contains the VPN profile configuration files. If you need to generate configuration files, see Download the VPN client profile configuration package.

After you obtain the VPN client profile configuration package, extract the zip file. The zip file contains the AzureVPN folder. The AzureVPN folder contains the azurevpnconfig_aad.xml file or the azurevpnconfig.xml file, depending on whether your P2S configuration includes multiple authentication types. If you don't see azurevpnconfig_aad.xml or azurevpnconfig.xml, or you don't have an AzureVPN folder, verify that your VPN gateway is configured to use the OpenVPN tunnel type and that Azure Active Directory (Microsoft Entra ID) authentication is selected.

Modify Windows profile configuration files

If your P2S configuration uses a custom audience with your Microsoft-registered App ID, you might receive popups each time you connect that require you to enter your credentials again and complete authentication. Retrying authentication usually resolves the issue. This happens because the VPN client profile needs both the custom audience ID, and the Microsoft application ID. To prevent this, modify your profile configuration .xml file to include both the custom application ID and the Microsoft application ID.

Note

This step is necessary for P2S gateway configurations that use a custom audience value and your registered app is associated with the Microsoft-registered Azure VPN Client app ID. If this doesn't apply to your P2S gateway configuration, you can skip this step.

  1. To modify the Azure VPN Client configuration .xml file, open the file using a text editor such as Notepad.

  2. Next, add the value for applicationid and save your changes. The following example shows the application ID value c632b3df-fb67-4d84-bdcf-b95ad541b5c8.

    Example

    
       {customAudienceID}
       https://sts.windows.net/{tenant ID value}/
       https://login.microsoftonline.com/{tenant ID value}/
       c632b3df-fb67-4d84-bdcf-b95ad541b5c8 
    
    

For Windows Azure VPN Client profiles, an additional field for Device Single Sign On (SSO) is enabled for ease of user authentication. Read more on Azure VPN Client and Device SSO.

Configure the Azure VPN Client for Windows and connect

Note

We're in the process of changing the Azure VPN Client fields for Azure Active Directory to Microsoft Entra ID. If you see Microsoft Entra ID fields referenced in this article, but don't yet see those values reflected in the client, select the comparable Azure Active Directory values.

  1. Open the Azure VPN Client.

  2. Select + on the bottom left of the page, then select Import.

  3. Browse to the Azure VPN Client profile configuration folder that you extracted. Open the AzureVPN folder and select the client profile configuration file (azurevpnconfig_aad.xml or azurevpnconfig.xml). Select Open to import the file.

  4. On the client profile page, notice that many of the settings are already specified. The preconfigured settings are contained in the VPN client profile package that you imported. Even though most of the settings are already specified, you need to configure settings specific to the client computer.

  5. Change the name of the Connection name (optional). In this example, notice that the Audience value shown is the value that's associated to the Microsoft-registered Azure VPN Client App ID. The value in this field must match the value that your P2S VPN gateway is configured to use.

    Screenshot shows Save the profile.

  6. Click Save to save the connection profile.

  7. In the left pane, select the connection profile that you want to use. Then click Connect to initiate the connection.

  8. Authenticate using your credentials, if prompted.

  9. Once connected, the icon turns green and shows Connected.

  10. The Azure VPN Client system tray, available in version 4.0.0.0 and later, lets you close the Azure VPN Client application while keeping the connection active. When you close the application, you can see the application in the Windows system tray. You can reopen the Azure VPN Client app in compact mode by clicking the tray icon.

    Screenshot of the Azure VPN Client.

Export and distribute a client profile

Once you have a working profile and need to distribute it to other users, you can export it using the following steps:

  1. Highlight the VPN client profile that you want to export, select the ..., then select Export.

    Screenshot that shows the Azure VPN Client page, with the ellipsis selected and Export highlighted.

  2. Select the location that you want to save this profile to, leave the file name as is, then select Save to save the xml file.

Delete a client profile

  1. Highlight the VPN client profile that you want to export, select the ..., then select Remove.

  2. On the confirmation popup, select Remove to delete.

Work with Windows connections

Connect automatically

You can configure your connection to connect automatically with Always-on.

  1. On the home page for your VPN client, select VPN Settings. If you see the switch apps dialog box, select Yes.

    Screenshot of the VPN home page with VPN Settings selected.

  2. If the profile that you want to configure is connected, disconnect the connection, then highlight the profile and select the Connect automatically check box.

    Screenshot of the Settings window, with the Connect automatically box checked.

  3. Select Connect to initiate the VPN connection.

Diagnose connection issues

Prerequisites check

If your Azure VPN Client is version 4.0.0.0 or later, you can run a prerequisites check to verify that your computer has the necessary items configured and installed to successfully connect. To view the version number of an installed Azure VPN Client, launch the client and select Help.

  1. Select the ... at the bottom of the Azure VPN Client page, and then select Prerequisites.
  2. On the Test Application Prerequisites page, select Run Prerequisites Test.
  3. Fix any issues and try connecting again. For more information, see Azure VPN Client prerequisites check.

Diagnostics tool

  1. Select the ... next to the VPN connection that you want to diagnose to reveal the menu. Then select Diagnose.

  2. On the Connection Properties page, select Run Diagnostics. If asked, sign in with your credentials, then view the results.

    Screenshot of the ellipsis and Diagnose selected.

Configure Windows custom settings: DNS and routing

You can configure the Azure VPN Client with optional configuration settings such as additional DNS servers, custom DNS, forced tunneling, custom routes, and other settings. For more information, see Azure VPN Client - optional settings.

Configure Device SSO for Windows

Device Single Sign On (SSO) allows users to sign in to their devices once and use that authentication while using the Azure VPN Client. For steps, see Configure Device SSO for Windows - Azure VPN Client – Microsoft Entra ID authentication.

Microsoft Entra ID authentication only supports OpenVPN protocol connections and requires the Azure VPN Client. The Azure VPN client for macOS isn't available in France and China due to local regulations and requirements.

  • Verify the client computer is running a supported OS on a supported processor.

    • Supported macOS releases: 15 (Sequoia), 14 (Sonoma), 13 (Ventura), 12 (Monterey)
    • Supported processors: x64, Arm64
  • If your device has an M-series chip and VPN client release earlier 2.7.101, you must install Rosetta software. For more information, see the Apple support article

  • If you’re using Azure VPN Client version 2.7.101 or later, you don’t need to install Rosetta software.

Workflow

  1. Download and install the Azure VPN Client for macOS.
  2. Extract the VPN client profile configuration files.
  3. Import the client profile settings to the VPN client.
  4. Create a connection and connect to Azure.

Download the Azure VPN Client

  1. Download the latest Azure VPN Client from the Apple Store.
  2. Install the client on your computer.

Extract client profile configuration files

Locate the VPN client profile configuration package that you generated. If you need to generate these files again, see the Prerequisites section. The VPN client profile configuration package contains the VPN profile configuration files.

When you generate and download a VPN client profile configuration package, all the necessary configuration settings for VPN clients are contained in a VPN client profile configuration zip file. The VPN client profile configuration files are specific to the P2S VPN gateway configuration for the virtual network. If there are any changes to the P2S VPN configuration after you generate the files, such as changes to the VPN protocol type or authentication type, you need to generate new VPN client profile configuration files and apply the new configuration to all of the VPN clients that you want to connect.

Locate and unzip the VPN client profile configuration package and open the AzureVPN folder. In this folder, you'll see either the azurevpnconfig_aad.xml file or the azurevpnconfig.xml file, depending on whether your P2S configuration includes multiple authentication types. The .xml file contains the settings you use to configure the VPN client profile.

Modify profile configuration files

If your P2S configuration uses a custom audience with your Microsoft-registered App ID, you might receive popups each time you connect that require you to enter your credentials again and complete authentication. Retrying authentication usually resolves the issue. This happens because the VPN client profile needs both the custom audience ID, and the Microsoft application ID. To prevent this, modify your profile configuration .xml file to include both the custom application ID and the Microsoft application ID.

Note

This step is necessary for P2S gateway configurations that use a custom audience value and your registered app is associated with the Microsoft-registered Azure VPN Client app ID. If this doesn't apply to your P2S gateway configuration, you can skip this step.

  1. To modify the Azure VPN Client configuration .xml file, open the file using a text editor such as Notepad.

  2. Next, add the value for applicationid and save your changes. The following example shows the application ID value c632b3df-fb67-4d84-bdcf-b95ad541b5c8.

    Example

    
       {customAudienceID}
       https://sts.windows.net/{tenant ID value}/
       https://login.microsoftonline.com/{tenant ID value}/
       c632b3df-fb67-4d84-bdcf-b95ad541b5c8 
    
    

For Windows Azure VPN Client profiles, an additional field for Device Single Sign On (SSO) is enabled for ease of user authentication. Read more on Azure VPN Client and Device SSO.

Import VPN client profile configuration files

Note

We're in the process of changing the Azure VPN Client fields for Azure Active Directory to Microsoft Entra ID. If you see Microsoft Entra ID fields referenced in this article, but don't yet see those values reflected in the client, select the comparable Azure Active Directory values.

  1. On the Azure VPN Client page, select Import.

  2. Navigate to the folder containing the file that you want to import, select it, then click Open.

  3. On this screen, notice the connection values are populated using the values in the imported VPN client configuration file.

    • Verify that the Certificate Information value shows DigiCert Global Root G2, rather than the default or blank. Adjust the value if necessary.
    • Notice the Client Authentication values align with the values that were used to configure the VPN gateway for Microsoft Entra ID authentication. This field must reflect the same value that your gateway is configured to use.

    Screenshot of Azure VPN Client saving the imported profile settings.

  4. Click Save to save the connection profile configuration.

  5. In the VPN connections pane, select the connection profile that you saved. Then, click Connect.

  6. Once connected, the status changes to Connected. To disconnect from the session, click Disconnect.

Create a connection manually

  1. Open the Azure VPN Client. At the bottom of the client, select Add to create a new connection.

  2. On the Azure VPN Client page, you can configure the profile settings. Change the Certificate Information value to show DigiCert Global Root G2, rather than the default or blank, then click Save.

    Configure the following settings:

    • Connection Name: The name by which you want to refer to the connection profile.
    • VPN Server: This name is the name that you want to use to refer to the server. The name you choose here doesn't need to be the formal name of a server.
    • Server Validation
      • Certificate Information: DigiCert Global Root G2
      • Server Secret: The server secret.
    • Client Authentication
      • Authentication Type: Microsoft Entra ID
      • Tenant: Name of the tenant.
      • Audience: The Audience value must match the value that your P2S gateway is configured to use. Typically, this value is c632b3df-fb67-4d84-bdcf-b95ad541b5c8.
      • Issuer: Name of the issuer.
  3. After filling in the fields, click Save.

  4. In the VPN connections pane, select the connection profile that you configured. Then, click Connect.

Remove a VPN connection profile

You can remove the VPN connection profile from your computer.

  1. Open the Azure VPN Client.
  2. Select the VPN connection that you want to remove, then click Remove.

Optional macOS client configuration settings

You can configure the Azure VPN Client with optional settings, such as additional DNS servers, custom DNS, forced tunneling, and custom routes. For a description of the available settings and configuration steps, see Azure VPN Client optional settings.

Important

The Azure VPN Client for Linux (Preview) retired on 31 August, 2026. After this date, the client is no longer supported. For more information, see the Azure VPN Client for Linux Retirement overview and migration guide for VPN Gateway and Virtual WAN.

Microsoft Entra ID authentication on Linux was available only through the retired Azure VPN Client for Linux. The supported OpenVPN and strongSwan alternatives don't support Microsoft Entra ID authentication with Azure VPN Gateway P2S connections.

To continue using Linux, change the gateway to a supported authentication method and migrate to a supported client. For available options and migration steps, see Migrate from the Azure VPN Client for Linux.

If Microsoft Entra ID authentication is required, use the Azure VPN Client for Windows or macOS.

Next steps