Info icon
End of Life Notice: For Trend Cloud One™ - Conformity Customers, Conformity will reach its End of Sale on “July 31st, 2025” and End of Life “July 31st, 2026”. The same capabilities and much more is available in TrendAI Vision One™ Cloud Risk Management. For details, please refer to Upgrade to TrendAI Vision One™

Enable Azure Active Directory Authentication for Azure VPN Gateway Point-to-Site

TrendAI Vision One™ provides continuous assurance that gives peace of mind for your cloud infrastructure, delivering over 1400 automated best practice checks.

Risk Level: Medium (should be achieved)
Rule ID: VPNGateway-001

Ensure that your Microsoft Azure VPN Gateway is configured to use Azure Active Directory (Microsoft Entra ID) as the sole authentication type for point-to-site (P2S) connections. Azure VPN Gateway supports multiple authentication types for point-to-site configurations, including Azure certificate, RADIUS authentication, and Azure Active Directory. Configuring Azure Active Directory as the only authentication type ensures that all P2S connections are authenticated through Microsoft's centralized identity management system, preventing the concurrent use of static credentials or certificate-based authentication for VPN access.

Security

Using Azure Active Directory (Microsoft Entra ID) as the exclusive authentication type for VPN Gateway point-to-site connections provides strong security through centralized identity management and eliminates risks associated with static credentials and certificate management. Certificate-based and RADIUS authentication methods rely on credentials that can be compromised, mismanaged, or shared without central oversight. Microsoft Entra ID enforces modern authentication controls including multi-factor authentication (MFA), conditional access policies, and integration with organizational user lifecycle management, enabling automatic access revocation when users leave the organization and providing comprehensive audit logs for all connection attempts.


Audit

To determine if your Microsoft Azure VPN Gateway is configured to use Azure Active Directory as the only authentication type for point-to-site connections, perform the following operations:

Using Azure Console

  1. Sign in to the Microsoft Azure Portal.

  2. Navigate to Virtual network gateways blade available at https://portal.azure.com/#browse/Microsoft.Network%2FvirtualNetworkGateways to access your Azure VPN Gateways.

  3. Select the Azure subscription that you want to access from the Subscription equals all filter box and choose Apply.

  4. From the Type equals all filter box, select Equals and choose Virtual network gateway to list only the Azure VPN Gateways available in the selected subscription.

  5. Click on the name (link) of the Azure VPN Gateway that you want to examine.

  6. In the resource navigation panel, under Settings, select Point-to-site configuration to access the point-to-site VPN settings for the selected gateway.

  7. In the Point-to-site configuration page, check the Authentication type field. If the Authentication type value includes Azure certificate or RADIUS authentication (either alone or alongside Azure Active Directory), the selected Azure VPN Gateway is not configured to use Azure Active Directory as the only authentication type and is therefore not compliant.

  8. Repeat steps no. 5 – 7 for each Azure VPN Gateway available in the selected subscription.

  9. Repeat steps no. 3 – 8 for each subscription available within your Microsoft Azure account.

Using Azure CLI

  1. Run account list command (Windows/macOS/Linux) with custom output filters to list the IDs of the cloud subscriptions available in your Azure cloud account:

    az account list
    --query '[*].id'
    
  2. The command output should return the requested subscription identifiers (IDs):

    [
        "abcdabcd-1234-abcd-1234-abcdabcdabcd",
        "abcd1234-abcd-1234-abcd-abcd1234abcd"
    ]
    
  3. Run account set command (Windows/macOS/Linux) with the ID of the Azure cloud subscription that you want to examine as the identifier parameter to set the selected subscription to be the current active subscription (the command does not produce an output):

    az account set
    --subscription abcdabcd-1234-abcd-1234-abcdabcdabcd
    
  4. Run resource list command (Windows/macOS/Linux) with output query filters to list the name and the associated resource group for each Azure VPN Gateway available in the selected subscription:

    az resource list
    --resource-type "Microsoft.Network/virtualNetworkGateways"
    --query '[*].{name:name, resourceGroup:resourceGroup}'
    --output table
    
  5. The command output should return the requested VPN Gateway names:

    Name                         ResourceGroup
    ---------------------------  ------------------------------
    cc-main-vpn-gateway          cc-main-resource-group
    cc-project5-vpn-gateway      cc-project5-resource-group
    
  6. Run network vnet-gateway show command (Windows/macOS/Linux) with the name of the Azure VPN Gateway that you want to examine and the associated resource group as the identifier parameters to retrieve the authentication types configured for point-to-site connections:

    az network vnet-gateway show
    --name cc-main-vpn-gateway
    --resource-group cc-main-resource-group
    --query "vpnClientConfiguration.vpnAuthenticationTypes"
    
  7. The command output should return the configured authentication type values:

    [
        "AAD"
    ]
    

    If the network vnet-gateway show command output returns only "AAD", as shown in the output example above, the selected Azure VPN Gateway is configured to use Azure Active Directory as the only authentication type and is compliant. If the output includes "Certificate" or "Radius" (either alone or alongside "AAD"), the selected VPN Gateway point-to-site configuration is not compliant.

  8. Repeat steps no. 6 and 7 for each Azure VPN Gateway available within the current subscription.

  9. Repeat steps no. 3 – 8 for each subscription available within your Microsoft Azure account.

Remediation / Resolution

To configure your Microsoft Azure VPN Gateway to use Azure Active Directory (Microsoft Entra ID) as the only authentication type for point-to-site connections, perform the following operations:

Important: Changing the authentication type on an active VPN Gateway point-to-site configuration will disconnect all existing VPN clients. Ensure that affected users download and configure the updated Azure VPN Client profile after completing the remediation steps.

Using Azure Console

  1. Sign in to the Microsoft Azure Portal.

  2. Navigate to Virtual network gateways blade available at https://portal.azure.com/#browse/Microsoft.Network%2FvirtualNetworkGateways.

  3. Select the Azure subscription that you want to access from the Subscription equals all filter box and choose Apply.

  4. From the Type equals all filter box, select Equals and choose Virtual network gateway.

  5. Click on the name (link) of the Azure VPN Gateway that you want to reconfigure (see Audit section part I to identify the right resource).

  6. In the resource navigation panel, under Settings, select Point-to-site configuration.

  7. In the Authentication type section, choose to expand the dropdown and perform the following:

    1. Check the box next to Azure Active Directory.

    2. Uncheck the boxes next to Azure certificate and RADIUS authentication.

  8. In the Microsoft Entra ID section, provide the following values:

    1. For Tenant, enter the URL for your Microsoft Entra tenant in the format https://login.microsoftonline.com/<TenantID>/.

    2. For Audience, enter the App ID for the Microsoft-registered Azure VPN Client: c632b3df-fb67-4d84-bdcf-b95ad541b5c8.

    3. For Issuer, enter the Secure Token Service URL in the format https://sts.windows.net/<TenantID>/.

  9. Choose Save at the top of the page to apply the changes.

  10. Repeat steps no. 5 – 9 for each Azure VPN Gateway that requires remediation in the selected subscription.

  11. Repeat steps no. 3 – 10 for each subscription available within your Microsoft Azure account.

Using Azure CLI

  1. Run account list command (Windows/macOS/Linux) with custom output filters to list the IDs of the cloud subscriptions available in your Azure cloud account:

    az account list
    --query '[*].id'
    
  2. The command output should return the requested subscription identifiers (IDs):

    [
        "abcdabcd-1234-abcd-1234-abcdabcdabcd",
        "abcd1234-abcd-1234-abcd-abcd1234abcd"
    ]
    
  3. Run account set command (Windows/macOS/Linux) with the ID of the Azure cloud subscription that you want to examine as the identifier parameter to set the selected subscription to be the current active subscription (the command does not produce an output):

    az account set
    --subscription abcdabcd-1234-abcd-1234-abcdabcdabcd
    
  4. Run network vnet-gateway update command (Windows/macOS/Linux) to configure the Azure VPN Gateway to use Azure Active Directory as the only authentication type for point-to-site connections (see Audit section part II to identify the right resource):

    az network vnet-gateway update
    --name cc-main-vpn-gateway
    --resource-group cc-main-resource-group
    --vpn-auth-type AAD
    --aad-tenant "https://login.microsoftonline.com/abcd1234-abcd-1234-abcd-1234abcd1234/"
    --aad-audience "c632b3df-fb67-4d84-bdcf-b95ad541b5c8"
    --aad-issuer "https://sts.windows.net/abcd1234-abcd-1234-abcd-1234abcd1234/"
    

    The --aad-audience value c632b3df-fb67-4d84-bdcf-b95ad541b5c8 is the fixed Microsoft-registered Azure VPN Client application ID. This value is a well-known constant published by Microsoft and does not need to be substituted with a per-tenant value.

  5. Run network vnet-gateway show command (Windows/macOS/Linux) to verify the updated authentication type configuration:

    az network vnet-gateway show
    --name cc-main-vpn-gateway
    --resource-group cc-main-resource-group
    --query "vpnClientConfiguration.vpnAuthenticationTypes"
    
  6. The command output should return the updated authentication configuration:

    [
        "AAD"
    ]
    
  7. Repeat steps no. 4 – 6 for each Azure VPN Gateway that requires remediation within the current subscription.

  8. Repeat steps no. 3 – 7 for each subscription available within your Microsoft Azure account.

References

Publication date May 19, 2026