Identify the VPN Server application before scoping Conditional Access

Which cloud application receives the VPN Conditional Access policy?

Governed cloud identity system with connected service and lifecycle nodes.
DSE visual intelligenceIdentity & cloudGuide · 2 min read
Executive summary

What you need to know

Which cloud application receives the VPN Conditional Access policy?

Potentially affected

Administrators configuring the documented Microsoft Entra Conditional Access integration for Always On VPN.

DSE recommendation

Have the identity owner locate the VPN Server application and establish whether the one-time consent step has been completed.

Source facts

Microsoft documents a VPN Server cloud application used by the VPN Conditional Access integration. Creating the first VPN root certificate automatically creates that application in the tenant. The initial consent step requires a Global Administrator and is performed once per tenant; subsequent certificate operations do not require consent again. Microsoft Learn.

Applicability

This check belongs to the documented Always On VPN integration, not every VPN product connected to a tenant. Confirm that its infrastructure and management prerequisites apply. Identify the actual tenant and application before planning policy scope or interpreting an access result.

DSE recommendation

Have the identity owner locate the VPN Server application and establish whether the one-time consent step has been completed. Record the tenant and application identifiers in the change record without including secrets or private keys. Build the proposed policy around a small, named test population and its expected access conditions. Keep policy targeting review separate from the certificate-upload procedure.

Verification

Inspect the saved policy target and confirm it is the intended VPN application, not a similarly named enterprise application. Perform an allowed and a disallowed sign-in under the approved test conditions. Correlate the resulting identity records with the selected policy and resolve unexpected targeting before expanding the population.

Official references

Microsoft Learn: Configure Conditional Access for VPN connectivity using Microsoft Entra ID. Source reviewed September 8, 2026.

Primary reference

Review the official source

Configure Conditional Access for VPN connectivity using Microsoft Entra ID · Verified September 8, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE