{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-296-refresh-windows-p2s-client-profiles-after-changing-an-azure-files-vpn-gateway/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-296-refresh-windows-p2s-client-profiles-after-changing-an-azure-files-vpn-gateway/",
        "slug": "dse-20260909-296-refresh-windows-p2s-client-profiles-after-changing-an-azure-files-vpn-gateway",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-296-refresh-windows-p2s-client-profiles-after-changing-an-azure-files-vpn-gateway/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-296-refresh-windows-p2s-client-profiles-after-changing-an-azure-files-vpn-gateway.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-296-refresh-windows-p2s-client-profiles-after-changing-an-azure-files-vpn-gateway/"
        },
        "title": "Refresh Windows P2S client profiles after changing an Azure Files VPN gateway",
        "summary": "A gateway's changed tunnel, certificate or authentication settings can leave previously installed client packages stale.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "managed-it",
            "label": "Managed IT operations",
            "alt": "A controlled technology lifecycle progressing from assessment to approved production.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/managed-it-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/managed-it-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:27:00+00:00",
        "modified_at": "2026-09-10T01:23:49+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 241,
        "potentially_affected": "Windows point-to-site VPN clients used to reach Azure Files SMB shares.",
        "dse_recommendation": "Include regeneration and client installation of the gateway-specific profile in the change's acceptance plan.",
        "primary_source": {
            "name": "Configure a Point-to-Site VPN on Windows for Azure Files | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/storage/files/storage-files-configure-p2s-vpn-windows",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft&#8217;s Azure Files P2S guidance explains that the downloadable Windows client package contains settings specific to the VPN gateway. Changes to the tunnel type, certificate or authentication type require a newly generated package to be installed on each client; otherwise clients might fail to connect.</p>\n<p>The documented Windows installer requires local administrator rights, and its package must match the computer&#8217;s processor architecture. This guidance concerns SMB file-share access through the point-to-site connection. <a href=\"https://learn.microsoft.com/en-us/azure/storage/files/storage-files-configure-p2s-vpn-windows\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the affected gateway, Windows client population and approved SMB destination. Keep the profile update separate from a decision to redesign authentication or replace certificates.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends assigning a client-distribution owner before the gateway change begins. Record which package corresponds to the approved gateway configuration and how each client receives it. Include remote or infrequently connected users in that inventory. Preserve an approved support path for a client that cannot install the update, rather than treating a completed gateway operation as a completed end-user change.</p>\n<h2>Verification</h2>\n<p>On representative Windows clients, confirm the intended package was installed and establish a fresh VPN connection. Test access to the approved SMB share and record the client, gateway and package version or internal release identifier used. Investigate failures separately at profile installation, VPN connection and file-access stages. Complete the rollout only when the affected client population is accounted for.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/storage/files/storage-files-configure-p2s-vpn-windows\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Configure a Point-to-Site VPN on Windows for Azure Files</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nMicrosoft’s Azure Files P2S guidance explains that the downloadable Windows client package contains settings specific to the VPN gateway. Changes to the tunnel type, certificate or authentication type require a newly generated package to be installed on each client; otherwise clients might fail to connect.\nThe documented Windows installer requires local administrator rights, and its package must match the computer’s processor architecture. This guidance concerns SMB file-share access through the point-to-site connection. Microsoft Learn.\nApplicability\nIdentify the affected gateway, Windows client population and approved SMB destination. Keep the profile update separate from a decision to redesign authentication or replace certificates.\nDSE recommendation\nDSE recommends assigning a client-distribution owner before the gateway change begins. Record which package corresponds to the approved gateway configuration and how each client receives it. Include remote or infrequently connected users in that inventory. Preserve an approved support path for a client that cannot install the update, rather than treating a completed gateway operation as a completed end-user change.\nVerification\nOn representative Windows clients, confirm the intended package was installed and establish a fresh VPN connection. Test access to the approved SMB share and record the client, gateway and package version or internal release identifier used. Investigate failures separately at profile installation, VPN connection and file-access stages. Complete the rollout only when the affected client population is accounted for.\nOfficial references\nMicrosoft Learn: Configure a Point-to-Site VPN on Windows for Azure Files. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft’s Azure Files P2S guidance explains that the downloadable Windows client package contains settings specific to the VPN gateway. Changes to the tunnel type, certificate or authentication type require a newly generated package to be installed on each client; otherwise clients might fail to connect.\n\nThe documented Windows installer requires local administrator rights, and its package must match the computer’s processor architecture. This guidance concerns SMB file-share access through the point-to-site connection. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/storage/files/storage-files-configure-p2s-vpn-windows).\n\n## Applicability\n\nIdentify the affected gateway, Windows client population and approved SMB destination. Keep the profile update separate from a decision to redesign authentication or replace certificates.\n\n## DSE recommendation\n\nDSE recommends assigning a client-distribution owner before the gateway change begins. Record which package corresponds to the approved gateway configuration and how each client receives it. Include remote or infrequently connected users in that inventory. Preserve an approved support path for a client that cannot install the update, rather than treating a completed gateway operation as a completed end-user change.\n\n## Verification\n\nOn representative Windows clients, confirm the intended package was installed and establish a fresh VPN connection. Test access to the approved SMB share and record the client, gateway and package version or internal release identifier used. Investigate failures separately at profile installation, VPN connection and file-access stages. Complete the rollout only when the affected client population is accounted for.\n\n## Official references\n\n[Microsoft Learn: Configure a Point-to-Site VPN on Windows for Azure Files](https://learn.microsoft.com/en-us/azure/storage/files/storage-files-configure-p2s-vpn-windows). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-296-refresh-windows-p2s-client-profiles-after-changing-an-azure-files-vpn-gateway/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-296-refresh-windows-p2s-client-profiles-after-changing-an-azure-files-vpn-gateway/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-296-refresh-windows-p2s-client-profiles-after-changing-an-azure-files-vpn-gateway/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Refresh Windows P2S client profiles after changing an Azure Files VPN gateway",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-296-refresh-windows-p2s-client-profiles-after-changing-an-azure-files-vpn-gateway/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-296-refresh-windows-p2s-client-profiles-after-changing-an-azure-files-vpn-gateway/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-296-refresh-windows-p2s-client-profiles-after-changing-an-azure-files-vpn-gateway/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-296-refresh-windows-p2s-client-profiles-after-changing-an-azure-files-vpn-gateway/",
                "headline": "Refresh Windows P2S client profiles after changing an Azure Files VPN gateway",
                "description": "A gateway's changed tunnel, certificate or authentication settings can leave previously installed client packages stale.",
                "abstract": "A gateway's changed tunnel, certificate or authentication settings can leave previously installed client packages stale.",
                "articleBody": "Source facts\nMicrosoft’s Azure Files P2S guidance explains that the downloadable Windows client package contains settings specific to the VPN gateway. Changes to the tunnel type, certificate or authentication type require a newly generated package to be installed on each client; otherwise clients might fail to connect.\nThe documented Windows installer requires local administrator rights, and its package must match the computer’s processor architecture. This guidance concerns SMB file-share access through the point-to-site connection. Microsoft Learn.\nApplicability\nIdentify the affected gateway, Windows client population and approved SMB destination. Keep the profile update separate from a decision to redesign authentication or replace certificates.\nDSE recommendation\nDSE recommends assigning a client-distribution owner before the gateway change begins. Record which package corresponds to the approved gateway configuration and how each client receives it. Include remote or infrequently connected users in that inventory. Preserve an approved support path for a client that cannot install the update, rather than treating a completed gateway operation as a completed end-user change.\nVerification\nOn representative Windows clients, confirm the intended package was installed and establish a fresh VPN connection. Test access to the approved SMB share and record the client, gateway and package version or internal release identifier used. Investigate failures separately at profile installation, VPN connection and file-access stages. Complete the rollout only when the affected client population is accounted for.\nOfficial references\nMicrosoft Learn: Configure a Point-to-Site VPN on Windows for Azure Files. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:27:00+00:00",
                "dateModified": "2026-09-10T01:23:49+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-296-refresh-windows-p2s-client-profiles-after-changing-an-azure-files-vpn-gateway/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-296-refresh-windows-p2s-client-profiles-after-changing-an-azure-files-vpn-gateway/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Refresh Windows P2S client profiles after changing an Azure Files VPN gateway"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 241,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure a Point-to-Site VPN on Windows for Azure Files | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/storage/files/storage-files-configure-p2s-vpn-windows"
                }
            }
        ]
    }
}