question

PieroB-8179 avatar image
0 Votes"
PieroB-8179 asked LimitlessTechnology-2700 answered

Force to connect to corporate VPN

Hello, I manage Active Directory with almost 400 Windows clients.
How can I setup my policy for forcing the users to connect to AnyConnect corporate VPN before use the network?

So all traffic passes on the VPN? And with disconnected VPN the user can't surf the web?

thanks

windows-active-directorywindows-group-policy
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

piaudonn avatar image
0 Votes"
piaudonn answered

Although you could play with firewall policies and whatnot to allow only connections to your VPN endpoints while connected to the Internet I would strongly recommend you refer to your VPN vendor as they might have clients settings to allow this without the hussle of handling the config yourself.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

LimitlessTechnology-2700 avatar image
0 Votes"
LimitlessTechnology-2700 answered

Hello

Thank you for your question and reaching out.
I can understand you are having some queries related to VPN connection before using network.

This VPN profile setting "Trusted Network Detection" appears to fit the criterion. As a reference, You can read the following article.

https://docs.microsoft.com/en-us/mem/intune/configuration/vpn-settings-windows-10#trusted-network-detection

When this option is enabled, the device will only establish a VPN connection when it leaves the trusted network.

I hope it becomes useful.



--If the reply is helpful, please Upvote and Accept as answer--

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.