What you need to know
Which Always On VPN profile is needed before a user signs in?
Potentially affected
Administrators assessing the documented Always On VPN device-tunnel design.
DSE recommendation
Have the endpoint and network owners list the resources needed before sign-in separately from the resources needed by a signed-in user.
Source facts
A device tunnel can establish connectivity before user sign-in to support device management and other pre-logon scenarios. A user tunnel connects after user sign-in. The two tunnel profiles operate independently and can be connected simultaneously; the device tunnel uses IKEv2 and has no SSTP fallback. Microsoft Learn.
Applicability
Verify the client edition, version, domain membership, and certificate prerequisites against the current device-tunnel guidance. Identify the specific pre-logon management need. Do not assume that a working post-logon user connection proves the device profile is deployed or operational.
DSE recommendation
Have the endpoint and network owners list the resources needed before sign-in separately from the resources needed by a signed-in user. Review the device profile against the documented deployment context and IKEv2 path. Keep a tested user-access alternative while piloting the device connection. Limit the pilot to machines with known ownership and preserve their original VPN profile configuration.
Verification
On a representative pilot machine, observe the connection before sign-in and test only the approved pre-logon resource path. Then sign in and inspect the user profile independently. Include a network where IKEv2 cannot connect in the acceptance discussion, rather than assuming an SSTP fallback will rescue the device tunnel.
Official references
Microsoft Learn: Configure the VPN device tunnel in Windows client. Source reviewed September 8, 2026.
Review the official source
Configure the VPN device tunnel in Windows client · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE