Microsoft's VPN app for Windows 11 and macOS, needed for point-to-site connections that authenticate with Entra ID; you set it up by importing the azurevpnconfig.xml file from the profile package.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Azure VPN Client in context, with comparison tables and the common traps.
Terms in this definition
- VPN
Traffic sent through an encrypted tunnel across a public network, as in a site-to-site connection to a VPN gateway in an Azure GatewaySubnet.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- Microsoft Entra ID
Cloud identity service from Microsoft, previously named Azure AD, which provides the tenant behind Microsoft 365 and Azure.
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- azurevpnconfig.xml
Profile file for the Azure VPN Client, found in the P2S profile package downloaded once the gateway is set up for Entra ID authentication; users import it, or it is pushed out to them.
Related terms
- Audience
Setting on a point-to-site VPN gateway using Microsoft Entra ID authentication; it contains the app ID of the Azure VPN Client or of a custom app. Only a single Audience value is allowed per gateway.
- Custom audience
Lets each point-to-site gateway admit only certain groups: register an app, set its client ID as that gateway's Audience and authorise the Azure VPN Client app as a client, creating one such registration per gateway.
- Microsoft Entra ID authentication (P2S)
Authentication option for point-to-site VPN in which users sign in through Entra ID, so Conditional Access and MFA apply. You need the Azure VPN Client and the OpenVPN tunnel type.