Authentication option for point-to-site VPN in which users sign in through Entra ID, so Conditional Access and MFA apply. You need the Azure VPN Client and the OpenVPN tunnel type.
Also called Azure AD authentication.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Microsoft Entra ID authentication (P2S) in context, with comparison tables and the common traps.
Terms in this definition
- Authentication
Checking an identity claim made by a person, device or app, for instance by asking for a password plus an extra factor. Authorisation only happens once this step has succeeded.
- Point-to-site VPN
Connection type in which single client machines, rather than whole sites, tunnel into an Azure virtual network gateway. App Service gateway-required VNet integration relies on it too.
- Microsoft Entra ID
Cloud identity service from Microsoft, previously named Azure AD, which provides the tenant behind Microsoft 365 and Azure.
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
- MFA
Multifactor authentication: asking for another factor on top of a password at sign-in, usually required by a Conditional Access grant control.
- APPLY
Evaluates a table-valued expression for every row on its left, inside
FROM. Think ofOUTER APPLYas a left outer join andCROSS APPLYas an inner join. - Azure VPN Client
Microsoft's VPN app for Windows 11 and macOS, needed for point-to-site connections that authenticate with Entra ID; you set it up by importing the azurevpnconfig.xml file from the profile package.
- OpenVPN
Only this point-to-site tunnel type can use Microsoft Entra ID authentication. It is TLS-based, runs on TCP 443 and has clients for Android, iOS, Linux, macOS and Windows.
See Microsoft Entra ID authentication (P2S) in the full glossary