# Separate pre-logon device VPN from user VPN requirements

> Which Always On VPN profile is needed before a user signs in?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-249-separate-pre-logon-device-vpn-from-user-vpn-requirements/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:13:02+00:00
- Modified: 2026-09-08T18:29:34+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Which Always On VPN profile is needed before a user signs in?

## Potentially affected

Administrators assessing the documented Always On VPN device-tunnel design.

## DSE recommendation

Have the endpoint and network owners list the resources needed before sign-in separately from the resources needed by a signed-in user.

## Article

## Source facts

A device tunnel can establish connectivity before user sign-in to support device management and other pre-logon scenarios. A user tunnel connects after user sign-in. The two tunnel profiles operate independently and can be connected simultaneously; the device tunnel uses IKEv2 and has no SSTP fallback. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/remote/remote-access/vpn/vpn-device-tunnel-config).

## Applicability

Verify the client edition, version, domain membership, and certificate prerequisites against the current device-tunnel guidance. Identify the specific pre-logon management need. Do not assume that a working post-logon user connection proves the device profile is deployed or operational.

## DSE recommendation

Have the endpoint and network owners list the resources needed before sign-in separately from the resources needed by a signed-in user. Review the device profile against the documented deployment context and IKEv2 path. Keep a tested user-access alternative while piloting the device connection. Limit the pilot to machines with known ownership and preserve their original VPN profile configuration.

## Verification

On a representative pilot machine, observe the connection before sign-in and test only the approved pre-logon resource path. Then sign in and inspect the user profile independently. Include a network where IKEv2 cannot connect in the acceptance discussion, rather than assuming an SSTP fallback will rescue the device tunnel.

## Official references

[Microsoft Learn: Configure the VPN device tunnel in Windows client](https://learn.microsoft.com/en-us/windows-server/remote/remote-access/vpn/vpn-device-tunnel-config). Source reviewed September 8, 2026.

## Primary reference

- Name: Configure the VPN device tunnel in Windows client
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/remote/remote-access/vpn/vpn-device-tunnel-config
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Separate pre-logon device VPN from user VPN requirements,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-249-separate-pre-logon-device-vpn-from-user-vpn-requirements/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
