# Refresh Windows P2S client profiles after changing an Azure Files VPN gateway

> A gateway's changed tunnel, certificate or authentication settings can leave previously installed client packages stale.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-296-refresh-windows-p2s-client-profiles-after-changing-an-azure-files-vpn-gateway/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:27:00+00:00
- Modified: 2026-09-10T01:23:49+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

A gateway's changed tunnel, certificate or authentication settings can leave previously installed client packages stale.

## Potentially affected

Windows point-to-site VPN clients used to reach Azure Files SMB shares.

## DSE recommendation

Include regeneration and client installation of the gateway-specific profile in the change's acceptance plan.

## Article

## Source facts

Microsoft’s Azure Files P2S guidance explains that the downloadable Windows client package contains settings specific to the VPN gateway. Changes to the tunnel type, certificate or authentication type require a newly generated package to be installed on each client; otherwise clients might fail to connect.

The documented Windows installer requires local administrator rights, and its package must match the computer’s processor architecture. This guidance concerns SMB file-share access through the point-to-site connection. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/storage/files/storage-files-configure-p2s-vpn-windows).

## Applicability

Identify the affected gateway, Windows client population and approved SMB destination. Keep the profile update separate from a decision to redesign authentication or replace certificates.

## DSE recommendation

DSE recommends assigning a client-distribution owner before the gateway change begins. Record which package corresponds to the approved gateway configuration and how each client receives it. Include remote or infrequently connected users in that inventory. Preserve an approved support path for a client that cannot install the update, rather than treating a completed gateway operation as a completed end-user change.

## Verification

On representative Windows clients, confirm the intended package was installed and establish a fresh VPN connection. Test access to the approved SMB share and record the client, gateway and package version or internal release identifier used. Investigate failures separately at profile installation, VPN connection and file-access stages. Complete the rollout only when the affected client population is accounted for.

## Official references

[Microsoft Learn: Configure a Point-to-Site VPN on Windows for Azure Files](https://learn.microsoft.com/en-us/azure/storage/files/storage-files-configure-p2s-vpn-windows). Source retrieved September 9, 2026.

## Primary reference

- Name: Configure a Point-to-Site VPN on Windows for Azure Files | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/storage/files/storage-files-configure-p2s-vpn-windows
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Refresh Windows P2S client profiles after changing an Azure Files VPN gateway,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-296-refresh-windows-p2s-client-profiles-after-changing-an-azure-files-vpn-gateway/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
