Connection type in which single client machines, rather than whole sites, tunnel into an Azure virtual network gateway. App Service gateway-required VNet integration relies on it too.
Also called P2S.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Point-to-site VPN in context, with comparison tables and the common traps.
Terms in this definition
- Connection
Resource that attaches a virtual network gateway to its peer, which may be an ExpressRoute circuit, a second VNet gateway (Vnet2Vnet) or a local network gateway over IPsec. Resetting it recovers a single tunnel and avoids rebooting the whole gateway.
- Virtual network gateway
Lives in GatewaySubnet and comes in two types, ExpressRoute or VPN. Setting it as the next hop in a UDR routes traffic on-premises.
- App Service
Managed PaaS hosting for web apps and Web App for Containers, run in a sandbox without OS access. Deployment slots and autoscale start at the Standard tier.
- Gateway-required VNet integration
Legacy option letting App Service reach VNets located in a different region, by connecting over an SSTP point-to-site VPN into a route-based virtual network gateway. Because it carries extra gateway charges, it is being retired on 31 March 2027 and regional VNet integration replaces it.
Related terms
- Audience
Setting on a point-to-site VPN gateway using Microsoft Entra ID authentication; it contains the app ID of the Azure VPN Client or of a custom app. Only a single Audience value is allowed per gateway.
- Azure Network Adapter
Windows Admin Center option for linking a single Windows Server to a VNet by point-to-site VPN. If the VNet has no VPN gateway it creates one, taking about 25 minutes, and no VPN hardware is needed on premises.
- azurevpnconfig.xml
Profile file for the Azure VPN Client, found in the P2S profile package downloaded once the gateway is set up for Entra ID authentication; users import it, or it is pushed out to them.
- CA
Entity that issues digital certificates; point-to-site VPN needs one only when clients authenticate with root and client certificates, not when RADIUS or Entra ID is used.
- Client address pool
Range of private addresses handed out to point-to-site VPN clients; it must not overlap on-premises or VNet ranges and is set once the VPN gateway has been created.
- Microsoft Entra ID authentication (P2S)
Authentication option for point-to-site VPN in which users sign in through Entra ID, so Conditional Access and MFA apply. You need the Azure VPN Client and the OpenVPN tunnel type.
- New-AzVpnClientIpsecPolicy
Cmdlet in Az.Network producing a custom IPsec policy for point-to-site VPN clients. It is set on the gateway, not on a site-to-site connection.
- NPS
Network Policy Server, the RADIUS server role in Windows Server. It often authenticates point-to-site VPN users against AD DS and hosts the NPS extension for Entra MFA.