The point-to-site gateway choice of OpenVPN, IKEv2, SSTP or a mix, which has to suit the client software. Only OpenVPN connections can use Microsoft Entra ID authentication.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Tunnel type in context, with comparison tables and the common traps.
Terms in this definition
- OpenVPN
Only this point-to-site tunnel type can use Microsoft Entra ID authentication. It is TLS-based, runs on TCP 443 and has clients for Android, iOS, Linux, macOS and Windows.
- IKEv2
Open-standard IPsec key exchange protocol for site-to-site tunnels, also offered as a point-to-site tunnel type that authenticates with certificates or RADIUS. Authentication through Microsoft Entra ID is not possible with it.
- SSTP
A Microsoft P2S tunnel type based on TLS, for Windows clients alone, capped at 128 connections and authenticating by RADIUS or certificate but not Entra ID. It is being retired in favour of OpenVPN or IKEv2: no new enablement after 31 August 2026, and connections cease on 31 March 2027.
- Keyless authentication
Recommended way of calling AI services and models: rather than sending an API key, the caller presents a Microsoft Entra ID token and is authorised through an RBAC role.
Related terms
- Microsoft Entra ID authentication (P2S)
Authentication option for point-to-site VPN in which users sign in through Entra ID, so Conditional Access and MFA apply. You need the Azure VPN Client and the OpenVPN tunnel type.