A Microsoft P2S tunnel type based on TLS, for Windows clients alone, capped at 128 connections and authenticating by RADIUS or certificate but not Entra ID. It is being retired in favour of OpenVPN or IKEv2: no new enablement after 31 August 2026, and connections cease on 31 March 2027.
Also called Secure Socket Tunneling Protocol.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains SSTP in context, with comparison tables and the common traps.
Terms in this definition
- Point-to-site VPN
Connection type in which single client machines, rather than whole sites, tunnel into an Azure virtual network gateway. App Service gateway-required VNet integration relies on it too.
- Tunnel type
The point-to-site gateway choice of OpenVPN, IKEv2, SSTP or a mix, which has to suit the client software. Only OpenVPN connections can use Microsoft Entra ID authentication.
- TLS
Transport Layer Security, the encryption protocol for traffic like HTTPS and Bastion sessions over port 443. On a storage account, minimumTlsVersion fixes the oldest accepted version without opening any network access.
- RADIUS authentication
Way of authenticating point-to-site VPN users where the gateway passes credentials on to a RADIUS server, NPS for example, which validates them against on-premises AD DS.
- Certificate
Key Vault object holding an X.509 certificate, whose associated key and secret are managed alongside it.
- Microsoft Entra ID
Cloud identity service from Microsoft, previously named Azure AD, which provides the tenant behind Microsoft 365 and Azure.
- OpenVPN
Only this point-to-site tunnel type can use Microsoft Entra ID authentication. It is TLS-based, runs on TCP 443 and has clients for Android, iOS, Linux, macOS and Windows.
- IKEv2
Open-standard IPsec key exchange protocol for site-to-site tunnels, also offered as a point-to-site tunnel type that authenticates with certificates or RADIUS. Authentication through Microsoft Entra ID is not possible with it.
Related terms
- Gateway-required VNet integration
Legacy option letting App Service reach VNets located in a different region, by connecting over an SSTP point-to-site VPN into a route-based virtual network gateway. Because it carries extra gateway charges, it is being retired on 31 March 2027 and regional VNet integration replaces it.
- SSL
The forerunner of TLS, whose name is still applied to TLS. Terminating TLS at a load balancer is called SSL offload, and VPN Gateway's SSTP (SSL) and OpenVPN (SSL) P2S tunnels run TLS over TCP 443.