Skip to content

Setting up Always On VPN on Windows so the tunnel is always live.

Windows AOVPN has a Device Tunnel (before user login, for logon and GPO) and a User Tunnel (for personal resources). You need Intune or GPO plus a RasMan template plus RADIUS or certificate auth. Not fun to do by hand on more than 5 laptops.

Try this first

  1. 1Decide whether you need only User Tunnel or also Device Tunnel: User Tunnel is usually enough for SMB.
  2. 2Generate the profile XML, easiest route is the Microsoft VPN Profile Designer or an Intune policy template.
  3. 3Set up cert auth via your AD CS or Intune SCEP profile, password-only auth is not recommended.
  4. 4Test on one pilot laptop with logs, AOVPN errors live in Event Viewer under Application and Services Logs > Microsoft > Windows > VPN.

When to bring us in

You no longer have domain-joined laptops, everything is Entra-only: classic AOVPN is a fight, choose Microsoft Tunnel, Tailscale or a ZTNA solution instead.

See also

None of the above fits?

Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.

Who are you?

For the AI question we need your email and company, so we can follow up if the AI gets stuck, and to prevent abuse.

Limited to 2 questions per hour and 5 per day, kept lean so the AI stays useful. For more, contacting us directly works better for you and us.

Or skip the DIY entirely

Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.