{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-243-identify-the-vpn-server-application-before-scoping-conditional-access/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-243-identify-the-vpn-server-application-before-scoping-conditional-access/",
        "slug": "dse-20260908-243-identify-the-vpn-server-application-before-scoping-conditional-access",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-243-identify-the-vpn-server-application-before-scoping-conditional-access/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-243-identify-the-vpn-server-application-before-scoping-conditional-access.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-243-identify-the-vpn-server-application-before-scoping-conditional-access/"
        },
        "title": "Identify the VPN Server application before scoping Conditional Access",
        "summary": "Which cloud application receives the VPN Conditional Access policy?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:13:08+00:00",
        "modified_at": "2026-09-08T18:29:34+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 2,
        "word_count": 222,
        "potentially_affected": "Administrators configuring the documented Microsoft Entra Conditional Access integration for Always On VPN.",
        "dse_recommendation": "Have the identity owner locate the VPN Server application and establish whether the one-time consent step has been completed.",
        "primary_source": {
            "name": "Configure Conditional Access for VPN connectivity using Microsoft Entra ID",
            "url": "https://learn.microsoft.com/en-us/windows-server/remote/remote-access/how-to-aovpn-conditional-access",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft documents a VPN Server cloud application used by the VPN Conditional Access integration. Creating the first VPN root certificate automatically creates that application in the tenant. The initial consent step requires a Global Administrator and is performed once per tenant; subsequent certificate operations do not require consent again. <a href=\"https://learn.microsoft.com/en-us/windows-server/remote/remote-access/how-to-aovpn-conditional-access\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>This check belongs to the documented Always On VPN integration, not every VPN product connected to a tenant. Confirm that its infrastructure and management prerequisites apply. Identify the actual tenant and application before planning policy scope or interpreting an access result.</p>\n<h2>DSE recommendation</h2>\n<p>Have the identity owner locate the VPN Server application and establish whether the one-time consent step has been completed. Record the tenant and application identifiers in the change record without including secrets or private keys. Build the proposed policy around a small, named test population and its expected access conditions. Keep policy targeting review separate from the certificate-upload procedure.</p>\n<h2>Verification</h2>\n<p>Inspect the saved policy target and confirm it is the intended VPN application, not a similarly named enterprise application. Perform an allowed and a disallowed sign-in under the approved test conditions. Correlate the resulting identity records with the selected policy and resolve unexpected targeting before expanding the population.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/remote/remote-access/how-to-aovpn-conditional-access\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Configure Conditional Access for VPN connectivity using Microsoft Entra ID</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nMicrosoft documents a VPN Server cloud application used by the VPN Conditional Access integration. Creating the first VPN root certificate automatically creates that application in the tenant. The initial consent step requires a Global Administrator and is performed once per tenant; subsequent certificate operations do not require consent again. Microsoft Learn.\nApplicability\nThis check belongs to the documented Always On VPN integration, not every VPN product connected to a tenant. Confirm that its infrastructure and management prerequisites apply. Identify the actual tenant and application before planning policy scope or interpreting an access result.\nDSE recommendation\nHave the identity owner locate the VPN Server application and establish whether the one-time consent step has been completed. Record the tenant and application identifiers in the change record without including secrets or private keys. Build the proposed policy around a small, named test population and its expected access conditions. Keep policy targeting review separate from the certificate-upload procedure.\nVerification\nInspect the saved policy target and confirm it is the intended VPN application, not a similarly named enterprise application. Perform an allowed and a disallowed sign-in under the approved test conditions. Correlate the resulting identity records with the selected policy and resolve unexpected targeting before expanding the population.\nOfficial references\nMicrosoft Learn: Configure Conditional Access for VPN connectivity using Microsoft Entra ID. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft documents a VPN Server cloud application used by the VPN Conditional Access integration. Creating the first VPN root certificate automatically creates that application in the tenant. The initial consent step requires a Global Administrator and is performed once per tenant; subsequent certificate operations do not require consent again. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/remote/remote-access/how-to-aovpn-conditional-access).\n\n## Applicability\n\nThis check belongs to the documented Always On VPN integration, not every VPN product connected to a tenant. Confirm that its infrastructure and management prerequisites apply. Identify the actual tenant and application before planning policy scope or interpreting an access result.\n\n## DSE recommendation\n\nHave the identity owner locate the VPN Server application and establish whether the one-time consent step has been completed. Record the tenant and application identifiers in the change record without including secrets or private keys. Build the proposed policy around a small, named test population and its expected access conditions. Keep policy targeting review separate from the certificate-upload procedure.\n\n## Verification\n\nInspect the saved policy target and confirm it is the intended VPN application, not a similarly named enterprise application. Perform an allowed and a disallowed sign-in under the approved test conditions. Correlate the resulting identity records with the selected policy and resolve unexpected targeting before expanding the population.\n\n## Official references\n\n[Microsoft Learn: Configure Conditional Access for VPN connectivity using Microsoft Entra ID](https://learn.microsoft.com/en-us/windows-server/remote/remote-access/how-to-aovpn-conditional-access). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-243-identify-the-vpn-server-application-before-scoping-conditional-access/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-243-identify-the-vpn-server-application-before-scoping-conditional-access/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-243-identify-the-vpn-server-application-before-scoping-conditional-access/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Identify the VPN Server application before scoping Conditional Access",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-243-identify-the-vpn-server-application-before-scoping-conditional-access/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-243-identify-the-vpn-server-application-before-scoping-conditional-access/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-243-identify-the-vpn-server-application-before-scoping-conditional-access/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-243-identify-the-vpn-server-application-before-scoping-conditional-access/",
                "headline": "Identify the VPN Server application before scoping Conditional Access",
                "description": "Which cloud application receives the VPN Conditional Access policy?",
                "abstract": "Which cloud application receives the VPN Conditional Access policy?",
                "articleBody": "Source facts\nMicrosoft documents a VPN Server cloud application used by the VPN Conditional Access integration. Creating the first VPN root certificate automatically creates that application in the tenant. The initial consent step requires a Global Administrator and is performed once per tenant; subsequent certificate operations do not require consent again. Microsoft Learn.\nApplicability\nThis check belongs to the documented Always On VPN integration, not every VPN product connected to a tenant. Confirm that its infrastructure and management prerequisites apply. Identify the actual tenant and application before planning policy scope or interpreting an access result.\nDSE recommendation\nHave the identity owner locate the VPN Server application and establish whether the one-time consent step has been completed. Record the tenant and application identifiers in the change record without including secrets or private keys. Build the proposed policy around a small, named test population and its expected access conditions. Keep policy targeting review separate from the certificate-upload procedure.\nVerification\nInspect the saved policy target and confirm it is the intended VPN application, not a similarly named enterprise application. Perform an allowed and a disallowed sign-in under the approved test conditions. Correlate the resulting identity records with the selected policy and resolve unexpected targeting before expanding the population.\nOfficial references\nMicrosoft Learn: Configure Conditional Access for VPN connectivity using Microsoft Entra ID. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:13:08+00:00",
                "dateModified": "2026-09-08T18:29:34+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-243-identify-the-vpn-server-application-before-scoping-conditional-access/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-243-identify-the-vpn-server-application-before-scoping-conditional-access/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Identify the VPN Server application before scoping Conditional Access"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 222,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure Conditional Access for VPN connectivity using Microsoft Entra ID",
                    "url": "https://learn.microsoft.com/en-us/windows-server/remote/remote-access/how-to-aovpn-conditional-access"
                }
            }
        ]
    }
}