Separate pre-logon device VPN from user VPN requirements

Which Always On VPN profile is needed before a user signs in?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 1 min read
Executive summary

What you need to know

Which Always On VPN profile is needed before a user signs in?

Potentially affected

Administrators assessing the documented Always On VPN device-tunnel design.

DSE recommendation

Have the endpoint and network owners list the resources needed before sign-in separately from the resources needed by a signed-in user.

Source facts

A device tunnel can establish connectivity before user sign-in to support device management and other pre-logon scenarios. A user tunnel connects after user sign-in. The two tunnel profiles operate independently and can be connected simultaneously; the device tunnel uses IKEv2 and has no SSTP fallback. Microsoft Learn.

Applicability

Verify the client edition, version, domain membership, and certificate prerequisites against the current device-tunnel guidance. Identify the specific pre-logon management need. Do not assume that a working post-logon user connection proves the device profile is deployed or operational.

DSE recommendation

Have the endpoint and network owners list the resources needed before sign-in separately from the resources needed by a signed-in user. Review the device profile against the documented deployment context and IKEv2 path. Keep a tested user-access alternative while piloting the device connection. Limit the pilot to machines with known ownership and preserve their original VPN profile configuration.

Verification

On a representative pilot machine, observe the connection before sign-in and test only the approved pre-logon resource path. Then sign in and inspect the user profile independently. Include a network where IKEv2 cannot connect in the acceptance discussion, rather than assuming an SSTP fallback will rescue the device tunnel.

Official references

Microsoft Learn: Configure the VPN device tunnel in Windows client. Source reviewed September 8, 2026.

Primary reference

Review the official source

Configure the VPN device tunnel in Windows client · Verified September 8, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE