Only this point-to-site tunnel type can use Microsoft Entra ID authentication. It is TLS-based, runs on TCP 443 and has clients for Android, iOS, Linux, macOS and Windows.
Also called OpenVPN (SSL).
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains OpenVPN in context, with comparison tables and the common traps.
Terms in this definition
- Tunnel type
The point-to-site gateway choice of OpenVPN, IKEv2, SSTP or a mix, which has to suit the client software. Only OpenVPN connections can use Microsoft Entra ID authentication.
- Keyless authentication
Recommended way of calling AI services and models: rather than sending an API key, the caller presents a Microsoft Entra ID token and is authorised through an RBAC role.
- Agents (classic) API
First-generation Foundry Agent Service API, based on threads, messages and runs. It is deprecated, replaced by conversations and responses, and retires on 31 March 2027.
- TCP
A transport protocol that is connection-oriented.
- LAMP
Short for Linux, Apache, MySQL and PHP (Perl and Python also fill the P): a widely used open-source stack for web applications whose database is frequently Azure Database for MySQL.
Related terms
- Microsoft Entra ID authentication (P2S)
Authentication option for point-to-site VPN in which users sign in through Entra ID, so Conditional Access and MFA apply. You need the Azure VPN Client and the OpenVPN tunnel type.
- OpenVPN Connect
OpenVPN client from a third party, in 2.x and 3.x versions, that can be used for certificate-authenticated OpenVPN point-to-site but cannot handle Microsoft Entra ID authentication.
- SSL
The forerunner of TLS, whose name is still applied to TLS. Terminating TLS at a load balancer is called SSL offload, and VPN Gateway's SSTP (SSL) and OpenVPN (SSL) P2S tunnels run TLS over TCP 443.
- SSTP
A Microsoft P2S tunnel type based on TLS, for Windows clients alone, capped at 128 connections and authenticating by RADIUS or certificate but not Entra ID. It is being retired in favour of OpenVPN or IKEv2: no new enablement after 31 August 2026, and connections cease on 31 March 2027.
- Vpnconfig.ovpn
The OpenVPN client profile found in the point-to-site package and loaded into OpenVPN Connect for certificate authentication. Entra ID point-to-site does not use it.