# Identify the VPN Server application before scoping Conditional Access

> Which cloud application receives the VPN Conditional Access policy?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-243-identify-the-vpn-server-application-before-scoping-conditional-access/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:13:08+00:00
- Modified: 2026-09-08T18:29:34+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Which cloud application receives the VPN Conditional Access policy?

## Potentially affected

Administrators configuring the documented Microsoft Entra Conditional Access integration for Always On VPN.

## DSE recommendation

Have the identity owner locate the VPN Server application and establish whether the one-time consent step has been completed.

## Article

## Source facts

Microsoft documents a VPN Server cloud application used by the VPN Conditional Access integration. Creating the first VPN root certificate automatically creates that application in the tenant. The initial consent step requires a Global Administrator and is performed once per tenant; subsequent certificate operations do not require consent again. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/remote/remote-access/how-to-aovpn-conditional-access).

## Applicability

This check belongs to the documented Always On VPN integration, not every VPN product connected to a tenant. Confirm that its infrastructure and management prerequisites apply. Identify the actual tenant and application before planning policy scope or interpreting an access result.

## DSE recommendation

Have the identity owner locate the VPN Server application and establish whether the one-time consent step has been completed. Record the tenant and application identifiers in the change record without including secrets or private keys. Build the proposed policy around a small, named test population and its expected access conditions. Keep policy targeting review separate from the certificate-upload procedure.

## Verification

Inspect the saved policy target and confirm it is the intended VPN application, not a similarly named enterprise application. Perform an allowed and a disallowed sign-in under the approved test conditions. Correlate the resulting identity records with the selected policy and resolve unexpected targeting before expanding the population.

## Official references

[Microsoft Learn: Configure Conditional Access for VPN connectivity using Microsoft Entra ID](https://learn.microsoft.com/en-us/windows-server/remote/remote-access/how-to-aovpn-conditional-access). Source reviewed September 8, 2026.

## Primary reference

- Name: Configure Conditional Access for VPN connectivity using Microsoft Entra ID
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/remote/remote-access/how-to-aovpn-conditional-access
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Identify the VPN Server application before scoping Conditional Access,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-243-identify-the-vpn-server-application-before-scoping-conditional-access/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
