Way of authenticating point-to-site VPN users where the gateway passes credentials on to a RADIUS server, NPS for example, which validates them against on-premises AD DS.
Also called Remote Authentication Dial-In User Service, RADIUS.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains RADIUS authentication in context, with comparison tables and the common traps.
Terms in this definition
- Point-to-site VPN
Connection type in which single client machines, rather than whole sites, tunnel into an Azure virtual network gateway. App Service gateway-required VNet integration relies on it too.
- WHERE
Limits a SELECT, UPDATE or DELETE to just the rows meeting a condition. Omit it, and the statement hits every row.
- NPS
Network Policy Server, the RADIUS server role in Windows Server. It often authenticates point-to-site VPN users against AD DS and hosts the NPS extension for Entra MFA.
- AD DS
Short for Active Directory Domain Services, the domain controller-based Windows directory run on-premises. Microsoft Entra Domain Services offers a managed counterpart.
Related terms
- CA
Entity that issues digital certificates; point-to-site VPN needs one only when clients authenticate with root and client certificates, not when RADIUS or Entra ID is used.
- IKEv2
Open-standard IPsec key exchange protocol for site-to-site tunnels, also offered as a point-to-site tunnel type that authenticates with certificates or RADIUS. Authentication through Microsoft Entra ID is not possible with it.
- Microsoft Security Exposure Management
Posture solution found in the Defender portal. By bringing cloud, identity, endpoint and external attack surface assets into one enterprise exposure graph, it reveals which assets are critical, how attacks could travel, where choke points lie and how big the blast radius is.
- Microsoft Sentinel graph
Treats your security data as a web of connected entities, such as users, devices, resources and activities, alongside threat intelligence. Blast radius and the hunting graph are built on it, and custom graphs produced by an on-demand job are kept for 30 days.
- MSCHAPv2
When the NPS extension is used and the RADIUS client talks to NPS with this challenge-response protocol, MFA is limited to push notifications and phone calls. Code-based (TOTP) methods require PAP.
- PAP
Password Authentication Protocol, a RADIUS password protocol which, when used between NPS and the RADIUS client, lets the NPS extension support all Microsoft Entra MFA methods, TOTP codes from OATH tokens or Authenticator included.
- Set-AzVirtualNetworkGateway
Changes properties of the VPN gateway itself, for example RADIUS, protocols, the client IPsec policy or the P2S address pool, using Az.Network. For a connection's IPsec policy you need a different cmdlet.
- SSTP
A Microsoft P2S tunnel type based on TLS, for Windows clients alone, capped at 128 connections and authenticating by RADIUS or certificate but not Entra ID. It is being retired in favour of OpenVPN or IKEv2: no new enablement after 31 August 2026, and connections cease on 31 March 2027.