While implementing Autopilot Entra Hybrid Join with Always-On VPN recently, I ended up doing way more trial and error than I would have expected.
A core part of that was due to documentation being very decentralized, at least in my opinion.
It was very hard to know where to start. I ended up doing a ton of trial and error before nailing down all of the required components.
This will be a multi-part series done in an effort to help consolidate the steps of the process:
- VPN Gateway Configuration
- Always-On VPN Client Configuration
- Group Configuration
- Enrollment Status Page ESP
- CSP Configuration
References:
- Master:
- Always-On VPN Reference:
- Always-On VPN Certificate:

Leave a Reply