From 4001f90897f6d2bd5e140e4ea2b0e9e15104c4f7 Mon Sep 17 00:00:00 2001 From: jdeckerMS Date: Fri, 16 Sep 2016 08:37:29 -0700 Subject: [PATCH] remove proxy topic --- .../images/vpn-conditional-access-intune.png | Bin 0 -> 13283 bytes windows/keep-secure/vpn-authentication.md | 3 +-- windows/keep-secure/vpn-auto-trigger-profile.md | 1 - windows/keep-secure/vpn-conditional-access.md | 11 +++++++++-- windows/keep-secure/vpn-connection-type.md | 1 - windows/keep-secure/vpn-guide.md | 5 ++--- windows/keep-secure/vpn-name-resolution.md | 1 - windows/keep-secure/vpn-profile-options.md | 1 - windows/keep-secure/vpn-proxy-settings.md | 8 ++++++++ windows/keep-secure/vpn-routing.md | 1 - windows/keep-secure/vpn-security-features.md | 1 - 11 files changed, 20 insertions(+), 13 deletions(-) create mode 100644 windows/keep-secure/images/vpn-conditional-access-intune.png diff --git a/windows/keep-secure/images/vpn-conditional-access-intune.png b/windows/keep-secure/images/vpn-conditional-access-intune.png new file mode 100644 index 0000000000000000000000000000000000000000..9f4efabc3f5d8608e26132bd0b5d06fda5e7502c GIT binary patch literal 13283 zcmcJ0WmFtdmu&$F9tgpm;4Y23ySux)yCpzycSva59fG?%1PB%^xO;GWoo~LGHEZV0 z%v*20_oG(#yEhVM`08m|!gAE=U(!&Z{CII<> za#fKO0jeem4j_#;mcsJF08kr;^kn=N(nfHS(sl&^l)k?Q)R1F|8RR-IX)$3nFN2dT z)Mz?Q|1-<8iHU3^w1OWZIr1U5mBi8IR1PUvGWjcI#squ(2&mTOWv_QvO2LcH2PU#4 z!Y}ZNSmKHvjlY*@6Uu1S{xs009499Bh>mt7iz!>XmIq~-Y1o$fqZ)h=bNRTP_JCkPjKNE@7{REmE+|7$y{X^>As2ytZ~#Dv zes3y!VeT^Ii5LL7xrF$k01^ZxMF5b3{)r9%iNN(6;1l`(+}(>jSD%vgwfv_p=nVjb zMQ$H1m1*vV+X;ty<{QvNgT4InbjBmUj#19;ig;8hm5vE5s_gRtLR2k2KAo1@sT*x@ zsv4IAHpR2d=2nX7_a?=&BZ}lqK)3S8TAxO~g(>c_So3B&OkAo7wuw#Kxi51P7ak)N zrRKYbdU58GpQ^RM@4OS_)2$p&R`#)ef6HHxcNm(nCQHR zr_hkTN0lcYuY=iV>k^Ckec|qcS<8Nmea8p8Ts^>w15ceuI9*{0mx8X*U?aJ&Vo|+H zQlpx@ksJ6#CQW*6H#gGM;3Be`9+FUWzBN+QI7VtJl?*L|T%3}1TWy61UA%`E7r40{+$@W|R)ZRo z?1m7Cd{UOq19$Enjs=;F#Oc|3`v6E+G~VCw>30@kvof%bVp(cbpXYRK;eL?{p_cY| zPt&aaut5Dl$8W3;2N1vxYA7~R}{XdPAGBWyAE6 zd+}7n%;?R@1p<(cS+6yQ@K`!HjhofXUrFQO`gF(1gWGqB@bS|tKH($FY!H9tCFH&JcI2cMU>^3OVb}g z|8ZYqWr2xkhTNorWQTF?q$0yA+nelu9^8v%r(3pzJl)Y0IEmqDsem ziinP#2(!$pg(1F+To~~=VbfW@k0Bu^zWh{6qGi5-di9JFm*K57xK338pPWwoa-4fY zXUV|iQcb@KH*}!NPHjLvNQ5J4*FC?$Lqa++dsDq&O!hP~diLVoT9CpL3rJQ#&`zh5 zPA%?m3zwT{X#|((z_GT~4i~oCOH^&;otZCTA0{-RW|9VnY1EC1yw)4Q=)<@cKOJ3F z5}7=S|2Tp>K4z3PV=Z&`rm?AerF>QD3-A_ljh4Dxi1s)g;B{1dx1}H#x?kL4ff-bBocIGX7$0+Z?ucYk2l%M#BsmI zFMYM^oyUs4ut5T9n8sE3b=~7IL`GqzD_V%8sYNq&wim|2S3i;^Cv$x_&`n`6{4rHL zGul;!fjD6iCeFyb6|LRSM-n`3h&E7*D4XOOr{uqqh~HSW*5!gHsV6`FwgE4P^UV<$ zI8M+mE8g?X)t&fgIcs#)-n=gr>^9;l;;Ac+GK1zKZfhRarS=h2;CCrT9HpS$!LG6$ zHRrmAX|Rf&Y73?QA-vA3QEzCXMg~Tm zsfu#frINrN9x$33&*JqwJzlE+8-I*|e?&Ex`Lh)$;I|X>{~W~XpE~#U1a7&#-vH@v ziJ$i+chGP?58v`zR)CwmfpJ8+Zs(q+9VoyE`u`vn3ad?>4)zAWCbkEC7-RE8H%ibs z-gzul^pAX5W`L21+9QPl0A^@71%BzfmBvNU^yx0#ZK3h@74pQBwEmmR=PkjPEs3+n zK7hbp;Bjec?Z+5d93Sb_XKB~&pY`fYZx3Ehm{Ztk$K_NOWeP=lSS=?PDVoeI>%JiB z>-`q2$JIUFk+nv8+X9s^`gtjRL!+-(gQAbM&o!Y9^NXc77};UCE*z~w3$Pd&5`4KZ zd?++bgzCHd5hmbvRM|8Nq_e@v@*jb#Z>TlnTkk_D$e4 zuTJ#{?`@AH?YMXc1b|~5JMVYn{IqyQdaM%PX)hGH08EG7@O;d+#HymujD+B-rsdU|gAA9!w-X@wcz zJI0Lr)obih;gaVcx+hs~pFa=*Io<2GZ+@o-A#gF?Jwl=hGt_?(Q)+I#Bg$dFuP?b7{jwB?E5k)}?Ck7#=`< z873HT|I<9}`EG{p62hRla3C8aXJg~R-oxPFk%8~^QMI@H_LXY2_qC$IlF|su`^pEi zCQl}_rPExHla{slJ!64%?iiehb-4ju#8`4T5&jqjO9zLl*`Ww@ zs(m$1ZB)DWbfmi7#L$$LU14Z5V)9nw62&a{4B69DMmCTe8+vV!KCi4TEgj(067v)$ zUaQ(7X4u10JpTCV0DKZ1sIZ^9c7JG*KX&^wHQ)I312@Hv+2R*yUZc=25qrfn-sOl4 zUt(T&)aoRY{95K?bW+iK^Sr8DKU(9W*1!%7ivm*9D;f+jv$(fvT6ORGrmSd|Ul0`~ z&~l?jZ5R&%Ih3?VH;WFfV^TsI4)G2^p`KEon@ZLRH9CeAYi-S+z4REZ(LEM9ML+CEl6Ovhx^Pz3QDP+=55Mis{JPiCCtuh{ z8Jzv68Lf3lpL0a~)6zy-r}cAfCw6p}YP6^%%arYF%)~0cVHHx-ekpX*URzJDr8E_d z+(>a#6^pyRb(PY)&GaU+CKsA+QBQ^9j zxSsk;g-(i#sPuraZHi9+371BG;y&VYVm#CromlFm)`T#)JUNa-30zE2w#@7^ri>cB z#HhJuBvPpl$l^Urt0rzJn-|wlEZc-@a$^nAlr(=6#u7LQ!Jqo6s#x+xESqgan6>jL zqm!h9>*7bEtV7v{PhJHo-N+dYJ{}<_OG_)K0mH_cLm@KrsDU*}BU{y0Rq|GTERoK5 z)2J~n-on|0Y*;M!oY7XdgLt6;@}`m3=~E?7%fTU;h9D|YZ&`+buapaCd?n64fEcoq&<8$o39pWCaghLI7!!dYsYkVq{_tlaos{nEB_~L z$U-sf{bt@q>fK1;_wUK$dOW{b#vzES*HOo}`=~DV%fQzwQ0c4?CSy_RTHDY9%yc=5 z)fnR)NvDx^Fg?&KTh(gRFH$E(U4Kv$JTk6#I$iPFwn#z9>|Nj4Ur>FYN z)4grvzwVwG{Yw{F8Lsux6{i*HCIX;=?rGD_!==%i%x}H$3~GmiGUoL0Oi_a?mNd?NhVWy{I&Rf*O7pN~O zzf~DUK1()m`{ICu|LHAWq_0LIV}g%Q)pN>qPo~h>0 z^mk<2A1wi+u??~<`O_6CG-S9q=tFoj-!4inZia=h57Eh#5lr>do0F+oPsYI-$26QA zCPO%pJTRxGBCWygyb*br`2w8ulCTnFjjn@}#hwOni%S=`6wYCBP8-dppuE(iMt=F( zWXVwT>2UU-n@sq@=~0Vg2TyieNT%Tpdn{u+$64`qZdKJJPzGvirYud*v^L#x$U;CZ za`1DrvYCeEaTN-O?Wv3lOk+cZ&l-9@;a%zdTipE*tgZ-i<5byxE?(0<#n*~?Ch9kw?Am5T zEvhi5Ouk+GKLv>fx94WZ_sZu&GiQEM`};`3FUy@6)6(vu#vrdVI4ft-wFJaPvPjPS zw%!}&Wq$hPW9(j8>F{y&W%x}L30BU5$tV?~xdXR~(}dsDdsO3qkd3gNw5J?~&8%;J zHH9;W2-v6%Rmb#^TP6)Qc$M9pGR8@MeW>n(qwgH032OCODn|S&+9-4joczf&cHj8y zvbpOk?iT;55+$Sn=e(iu+Ge55LAJgL&pSyhhjlJN+I8@kK5t5X^DfkRpUxz$&4_V4 z%8AdJjLL6$aF98Q_|uy5{kNU4UNdg)Y4fX6w%0(jKcgYX{wp@=+%)?TkxT_{WPhW7 zLQjOk$KfziDh10#R+*&2>Hdh6mV=LWEIskX$0Wl!Qc<~ik7d#s zzx98dxUH6cqe#MU8W0aFvME2E7CSkk{;&zf#GE*_vKr3X^q77}|FzI(27a~+RX8>L zE`S=cFJw?=ze|?#q?~v=cAi3}T3RzUa-(r@@R|66pR7Q2CH%KyFLiRu)DyPHO4(2V zXV4M}t-RLf+MIa=;`kB_#BJSKRYQjI1-g{nx%DrLRXFoz0`uzrq*;W*Q!7^;T1l$H zgyJ0bi)kr~el(&fp(@Ix&TLq{(%X$GB05;xnwP(+k53r;W51p2!)f0>y?XtL%|nc{ zikhazYbP0`B?Fnw^IM*6HNvqPD!`fTa7VGA@)cE5wD}I{x^qlySvZ)GCY3B5*GRp% zsIs@DeZEbb8AIqT9@jEF&n)zb#5Pz-wP-#`t`Qgx&^XF93y)GjV8Nfrykz5FQ%+Wd z@Yw_Vshr}-=0J>SIUP*FrtLv_|I`+?GggmwS(DwR59w}DyT1m7!W^a(MtsVSrUPh0sD=4lS#t{&W!)$;#&N|kyU24}b27fJu z_P0Y_Fgc@{W6fg~$}Fs$y*X_wie?|oLAdU-*OW(|Hb0)PI})&oAJQR;&B{`}r8zv{ zBvpb@camH`#%gC%lNK|7DNubSM{pUL`lOt#)qj7r=ib0a0uh!zT~KSJ1t)ft^Mc+< zxycAWz)Mkii?1*$z}rEJ7B~ot|6TfQaX6rD-8I7jY7E_YvZ@7c9J?&fE_v^W9~XzVr#JRq9?#Mw zrMZRHwRF~3LfoL4(X9^kea!V?g-9(*!OOhIo{vxfD-^m@97K=v+(rY8)_dNpkkzYA zRobuc0T!^7zllDdAat|5g`CoT14;ku&d|@tJ5qexe7gt(AY**hUA}||YR=^Bpux3g z3(c$GXpyy-2wy?xN3Uh|6IRGjQP_dhaRBf*8AACx!#D7?=*sXeeH&@7`aa`mCnJAS zj{jEvDHRQ1H3dP&zAlcDeRUQNjYevCBueJ}lW;*@p9ePrazj|B*^euF&PI zvT5z1k+btK#*tUHM;f;t-7@uX>EQQ~1uz~xBG--7P@K)WHl(hY#+}%E6#a^Evmc1J za7~+IQ5CT9B;WOdfMvcOFsoaQ<-G3oP)G;%-!8Q@47e%1!tkpp`hIW3qIz8r2z

y`2@Qy&?KC;7~aLn z4j$Ou2|V8{FYUZuJVnv+dq4ZjW?7zAs`bjj5}t8t{S|CL2?$=fH@{^yyHa>JqVcP| zFJd2w3cM~m=X|JJ_NF}7>CmuG@5UU%IYs*27tTw51w&?pBH^Xz2>Eh_*zRczD$tf~ ztV^lMOLK>n*gqShsobQs3EX~3nL4f`X7ZlD+&>o;p^r;+`Sc<}2m!bSJOnivr9LLB z=%1E8BQ#4I`9eF%{lyilx}x9uf9!-HB#BDl*vJt8ETH5&=&GCb{=)M>t{9f@7HuE*Pg2IA?u)f+k-p+Vc8fOh{e_PT;0+3IRyYGuh0Ln++pnE z81sEV4WjUnB4hFVU3&jj9V7&|%k}k!^&~LR#@^L-vFa%;o5y{34||QH`os!Sc75zK z%KcjF^K!o~aQS(;j!F@nyul@<+jVyv7x24L7qSe2n;4kKn8NG|$9T8SyZp55*Pem1 zuJ_MRbB3=IkAinSfnIkT#D+fN2FxE1Q$!k-5w%56CX`yGTNJ)X?mn#5O z`V@9$uolE;k=>{jI&@hpnKhEc#l3?&*(DOSr~u>ZF8^`$H{Eit?s&LfXqWI;Fmyhg z^<1shqv_h?KWnhpB|rKiRvh+>-ict!!SgPOum-DC0;4>}1T0C6Y1P;kI(y)TH>ZE& z9R2>W&PMMO3lr^91}F3%@jYC}1ArGCb+mXNhV%_jW73 zaizkPYSS&@X7szv2p`l4B=mGLn_l~Ee2Mzw>KpbP<9+RYIf7*PFq5`+5$m~@*p{MD zYSz|w5*2ig+BRQep|_7E_IqTQYlwT?RDu7{J;a{${g-%Uk|0`saSX(_Xr&nn#^#{L zXd{*i=#<_>M;wn(ioKqyy(-%LCMol(G@K8!q+bl~9gegXq}?86Ng^ps7*Z6n|ij;-G!kSg?YRnz0H}Zm~VdIi|l% z;)hk($H}yw5tpDluN0?&$`?s-#u~Ux&Dffx60|rmd(A)sISNFHWsPVhDZ{`s6ht4# z&eK{)91F23lFqG5T(-Si$4pax5%!J2KAF9WqNFU$?T6HzEy!JDi?s+E$(v;JJwEPY zA$gR3$|$BPbXps+N2TkIk29_^%$p1PxJ%_8uIeH73zBJR#_%EIOfO3|36+O#z^RSB zkeW;e=Rce`t-9RW10?aOQv37U&ar&qVxy1mX)k@)WG8?GPny zv_CYuCV2ZiA{Xa?+lD{$ek-KauV%VJ95iocM$o#-IbZPsHs@1Ub-YAJSAP+oHs?&4 zeq%E%vMzu6hc=B*{a+&RmeND>*VWyd$eJ=iv%jpD|DE9(UEh@s+TTT`UCO~p8C)=-Sz z2js&My~b7}i4t-m4Sj!uzji<3d)l@+N;h);6tnK#r3I`mE`C^-BQ*0Jtn`)mc-6yF zFouh>`guT)4=sZ+49O7aWYM4*1Y_8I+F1i43I=nM783{l6cL@R4ETjvM)m-+9Ie zJdHdO-6bjV-3CXcG3w|2o>gohdfXNC-$xaopH#W73b;O4FucM`kQ;;ox;veX0vGnT zN6^3O>NG9oTJnbuAY@&3?6V@_g=nzy$W3O7#m6Iiyob*tPJaXiYu@7z4GTYH^Tsc=t-ko z-ijlzE-&xV(O2>;rkDMly+EgnM7^Rp9mlm4rjPslU9t%}lg(&|AtPwp$@vCPNi)nm=+GR?vDdd*WZf3_d3Urtix zesD#c(B-&>ujAP}$?L5zLMFXB;F-NzIeS*~+ruAyPkPPKGw&&1`(>;Vp9E2{1i5HR zkxs4Erb>*P`U;}$wE>r6)*=nO1aG<@>fjKSK^y!m?DCjz8!^6HW$#+f@Xfh%zfP9% z$84~+;0?~G+Rrguk4B<7yi|}%ew;7hx+L)VO9V32>~5RmrvhKD6!|XtS3TFC={VOG z<>w_=90rYO)im@P%o(jM2XEBYqb4?KTI0>}2}TwbX068budFnDBp9QsmNKe}FtD?R z15SX4Q#^c%3E-BwCj3u zDaH|HdHtq#WxMsupHr~f(qXD*7fWIVeV(AMLFdX{KsZ%-)oh!TK8|J#Sf6#tB5wn$ zIAnw~s(8QK5`SVutB;&4<9YqBYN$I{hGddLqJxF+`@y}Kl)V5af#hZ0 zio1kztY#j6!+!K-ld03Nx^W+?On2mZpvn~kBjMXA{reb|YwWby6ppUMUeeF=rYz{& z!%pe{Ec%_l;~Loe3`fM}yxC9uGCecz5jI(3_I#d8hVZ3ZQG0BqpC(KqW~J^MM5khR z_4^mTuwb0)ZL@8&S+TLSahLQX9pzT#Y+D7Sve5=b2ezc+C@%a{D3m(aRd2dk2Wx%= zYc_f%MYfXDj7_V2^7d>g!yz$wV9UnFc7?H0ef`h@JlR-+d`mYcqx2YYGps6RgV4z0 z(#`p8yI>}jS-JcH%Fe!sOjYonB0 zQ;s}8h{WHhz)NpScil&-y75z{wg-Lj_+d4#={8n@H~9{uAGFKi+Xk1+n7|h`^yTOJ z!jBUjR`V_i2rkK7{f9J-GyzYwL#M4rlj~2{%bmB!SBg(pO^kY8m#a&F`NzLjnMY~8`5e1Bjo$?_n?l;SCa@|IlX=6Vqs^G{+lA3LI zy&O&~Wq008d|f7dcu%YCA~KaQj`$LYO6MTGWD8yQ>t{Lg2gB7dGAp7w97+N<)aUTo zB~;wp+~%5;9{7kcJn+f;lKvmHC)yJPp)Q5o1sJVcG={2HQ7K{z#++CDwq$<(@|-#Q zMONj7A7=DGKrkEYHjQ&BMu#Lq{F%z|=vI#~au=B>JTbyWlV~%Vu|uUyzv~`9J(BHQ zsjsKBAd$td%K@Gb=Hi@j#9Da^2R9c+s81OS`uC-3zgvj;LX`hIPGR#;PBD#r0G-bZ zlOah@I=d6DtWm-7lLB`+O3prW+_=S#!CG@Rx3m)~iu8=R+UT65Zvr zTsaZ3prIbJ$a<<(F~R)jg2V$M3FUbQU0ixKlS%mXX>&V}cPp%Z`6=Ei<{YC1n4arn zodp=d(k4Lon=(Dm&aiI&M+|JjgE*!Z|BgZpy9{^1rmhyHl7GGE?5cr#q&bc(C; zWWNaNrz;}*)o67Ceo^pGtDbDA;oCK6nx*6!?8LDpG+{>;+d%uWWqRN2lF)bB6D+0O zgHhqz`XN3(1&{C&Ln@DZF8)R9-4D)}cCN@{reQ9pldc(VPte|LT!-{AIF z)6>e=eOKF?)!TsG+0FF8DvAS0xNP41qaJpr7~<9y0ZOdop;aCAcz>K_$HO|!R2}c; zBY`r5U@>gm!2fzX`+D2*db`59H)-E~85te9Ri@cx^HTJ6?Q+-l{@1Ma4&a(E)9$Pr6UZ53vv~9K%8Jy30t$dH zVj;@`OD0w3c6B2{oT+%M(1+e^5RLB>ik%`eZ4E!v4@g78+_jtW1|U#`oE=;2<8fPz zRg=ZNNQ`{?a&OR?LWv}CvyuCosL^*tkkQ~Nmk%0{vy>n(TvlCvU~awrC{4bO;@itB zeN3hM^^SoIXq7XS=yr|k_4r76KwyloZjo)nD@;VapFjf91!ptRhBW#67+!H~6es3< z#MggZoX>3dF2MkAX4BEmS8#LpPM50|R`Gl}F9!~L=CmOa&VKjJH;_jCw3S;XIBWWv z)v9`gOo7K8{-&7ddlWw~lw>^)Ut%c;DQVZUUOxK@NDh`@+gOh=v_Oh5Xx*(;K-d?^ z85O>uysFj=$9Wewuz1)ILF40n?xH9GM8MsLJn-)`Um|${7t8ypQ<@O~7y@szLID#dS$J-Y;elNF<$_rMN_nfrY5 z+3GT-TJU8@l2~_r5mI4}Wht(1z3gcE)^V@TIee}K5vcyMUS!yHEeN(o{<9@;4UbU1 z^Gfb^cgS?YrLu)OvH zR2DKz%)D%^LNhnrp@sG!uDSqw)lq#LTUf<%bP|jfTxDP zrvxGd3&Az+u@tITN4I(J?anv;69AIeW+vo|L(d^dOW-VCvYrUni%rxWh^oxPy2({m zoWaClYu@L=6H^w=<6>vO*%S@zgJN)@rn0PR4M#UHXx*_i21^%bvM7dSL~GTllGJ%q z;dxb>7tJ(3ke2J0Y9jK%gw{#Wks^uI$Ets;(_U(T8Mizhhx&x#v73&V(yP*{mp@6N zGKgpWJ5j%k-Md*^SNB~5tqk4QT6K^wjT*~(L#no3LwXv^M~LnI+Rh;qVFPMXA&TrMW#MP$>v{1(3W?y7%V@bnp#~Jt&x9>>rdbBj!Eqm}#N5HpX&}(Keoh1`)6g=7|z!`I7vb)@S_i|U`3lc$$u@zyA zE#UBxJ^BU_yn->9G?dUFcSXPr@`UHN{Be}TE%i^9x5;L}CsV~s+|ONS-Yfe?tLXoV zvA<5-zwKzme=Mfke*+j5PRc)oVOJD@iw(P~ebWU3R|tgJ?nf7hUoZ3HDjn^HnSr77 zf3FLB(ZeDU{@q|EjjAY_A%2_83faxOncP=R3U@K^0oR< zzV^vO9E{!0FkOH1Q{OlLu+c9D|7{H6{CB$Yf3)3q-{B0t!o5|H*3+dj9)`S_14xT2 Kh*gOg1^q9D)|`d_ literal 0 HcmV?d00001 diff --git a/windows/keep-secure/vpn-authentication.md b/windows/keep-secure/vpn-authentication.md index c26290863d..d772fd0e9b 100644 --- a/windows/keep-secure/vpn-authentication.md +++ b/windows/keep-secure/vpn-authentication.md @@ -25,7 +25,7 @@ Windows supports a number of EAP authentication methods. EAP-Microsoft Challenge Handshake Authentication Protocol version 2 (EAP-MSCHAPv2)
  • User name and password authentication
  • Winlogon credentials - can specify authentication with computer sign-in credentials
EAP-Transport Layer Security (EAP-TLS)
  • Supports the following types of certificate authentication
    • Certificate with keys in the software Key Storage Provider (KSP)
    • Certificate with keys in Trusted Platform Module (TPM) KSP
    • Smart card certficates
    • Windows Hello for Business certificate
  • Certificate filtering
    • Certificate filtering can be enabled to search for a particular certificate to use to authenticate with
    • Filtering can be Issuer-based or Enhanced Key Usage (EKU)-based
  • Server validation - with TLS, server validation can be toggled on or off
    • Server name - specify the server to validate
    • Server certificate - trusted root certificate to validate the server
    • Notification - specify if the user should get a notification asking whether to trust the server or not
Protected Extensible Authentication Protocol (PEAP)
  • Server validation - with PEAP, server validation can be toggled on or off
    • Server name - specify the server to validate
    • Server certificate - trusted root certificate to validate the server
    • Notification - specify if the user should get a notification asking whether to trust the server or not
  • Inner method - the outer method creates a secure tunnel inside while the inner method is used to complete the authentication
    • EAP-MSCHAPv2
    • EAP-TLS
  • Fast Reconnect: reduces the delay between an authentication request by a client and the response by the Network Policy Server (NPS) or other Remote Authentication Dial-in User Service (RADIUS) server. This reduces resource requirements for both client and server, and minimizes the number of times that users are prompted for credentials.
  • Cryptobinding: By deriving and exchanging values from the PEAP phase 1 key material (Tunnel Key) and from the PEAP phase 2 inner EAP method key material (Inner Session Key), it is possible to prove that the two authentications terminate at the same two entities (PEAP peer and PEAP server). This process, termed "cryptobinding", is used to protect the PEAP negotiation against "Man in the Middle" attacks.
-Tunneled Transport Layer Security (TTLS)
  • Inner method
    • Non-EAP
      • Password Authentication Protocol (PAP)
      • CHAP
      • MSCHAP
      • MSCHAPv2
    • EAP
      • MSCHAPv2
      • TLS
  • Server validation: in TTLS, the server must be validated. The following can be configured:
    • Server name
    • Trusted root certificate for server certificate
    • Whether there should be a server validation notification
+Tunneled Transport Layer Security (TTLS)
  • Inner method
    • Non-EAP
      • Password Authentication Protocol (PAP)
      • CHAP
      • MSCHAP
      • MSCHAPv2
    • EAP
      • MSCHAPv2
      • TLS
  • Server validation: in TTLS, the server must be validated. The following can be configured:
    • Server name
    • Trusted root certificate for server certificate
    • Whether there should be a server validation notification

@@ -47,7 +47,6 @@ The following image shows the field for EAP XML in a Microsoft Intune VPN profil - [VPN connection types](vpn-connection-type.md) - [VPN routing decisions](vpn-routing.md) - [VPN and conditional access](vpn-conditional-access.md) -- [VPN proxy settings](vpn-proxy-settings.md) - [VPN name resolution](vpn-name-resolution.md) - [VPN auto-triggered profile options](vpn-auto-trigger-profile.md) - [VPN security features](vpn-security-features.md) diff --git a/windows/keep-secure/vpn-auto-trigger-profile.md b/windows/keep-secure/vpn-auto-trigger-profile.md index 1583d8f784..6bce6b2514 100644 --- a/windows/keep-secure/vpn-auto-trigger-profile.md +++ b/windows/keep-secure/vpn-auto-trigger-profile.md @@ -25,7 +25,6 @@ localizationpriority: high - [VPN routing decisions](vpn-routing.md) - [VPN authentication options](vpn-authentication.md) - [VPN and conditional access](vpn-conditional-access.md) -- [VPN proxy settings](vpn-proxy-settings.md) - [VPN name resolution](vpn-name-resolution.md) - [VPN security features](vpn-security-features.md) - [VPN profile options](vpn-profile-options.md) \ No newline at end of file diff --git a/windows/keep-secure/vpn-conditional-access.md b/windows/keep-secure/vpn-conditional-access.md index 4b6e4190d7..0e655c592d 100644 --- a/windows/keep-secure/vpn-conditional-access.md +++ b/windows/keep-secure/vpn-conditional-access.md @@ -61,7 +61,7 @@ Server-side infrastructure requirements to support VPN device compliance include After the server side is set up, VPN admins can add the policy settings for conditional access to the VPN profile using the VPNv2 DeviceCompliance node. -Two client-side configuration service providers are leveraged for VPN Device Compliance. +Two client-side configuration service providers are leveraged for VPN device compliance. - VPNv2 CSP DeviceCompliance settings - **Enabled**: enables the Device Compliance flow from the client. If marked as **true**, the VPN client will attempt to communicate with Azure AD to get a certificate to use for authentication. The VPN should be set up to use certificate authentication and the VPN server must trust the server returned by Azure AD. @@ -75,8 +75,16 @@ Two client-side configuration service providers are leveraged for VPN Device Com - Provisions the Health Attestation Certificate received from the HAS - Upon request, forwards the Health Attestation Certificate (received from HAS) and related runtime information to the MDM server for verification +## Configure conditional access +See [VPN profile options](vpn-profile-options.md) and [VPNv2 CSP](https://msdn.microsoft.com/library/windows/hardware/dn914776.aspx) for XML configuration. +The following image shows conditional access options in a VPN Profile configuration policy using Microsoft Intune. + +![conditional access in profile](images/vpn-conditional-access-intune.png) + +>[!NOTE] +>In Intune, the certificate selected in **Select a client certificate for client authentication** does not set any VPNv2 CSP nodes. It is simply a way to tie the VPN profile’s successful provisioning to the existence of a certificate. If you are enabling conditional access and using the Azure AD short-lived certificate for both VPN server authentication and domain resource authentication, do not select a certificate since the short-lived certificate is not a certificate that would be on the user’s device yet. ## Learn more about Conditional Access and Azure AD Health @@ -91,7 +99,6 @@ Two client-side configuration service providers are leveraged for VPN Device Com - [VPN connection types](vpn-connection-type.md) - [VPN routing decisions](vpn-routing.md) - [VPN authentication options](vpn-authentication.md) -- [VPN proxy settings](vpn-proxy-settings.md) - [VPN name resolution](vpn-name-resolution.md) - [VPN auto-triggered profile options](vpn-auto-trigger-profile.md) - [VPN security features](vpn-security-features.md) diff --git a/windows/keep-secure/vpn-connection-type.md b/windows/keep-secure/vpn-connection-type.md index 9347844294..ecd032bc82 100644 --- a/windows/keep-secure/vpn-connection-type.md +++ b/windows/keep-secure/vpn-connection-type.md @@ -76,7 +76,6 @@ In Intune, you can also include custom XML for third-party plug-in profiles. - [VPN routing decisions](vpn-routing.md) - [VPN authentication options](vpn-authentication.md) - [VPN and conditional access](vpn-conditional-access.md) -- [VPN proxy settings](vpn-proxy-settings.md) - [VPN name resolution](vpn-name-resolution.md) - [VPN auto-triggered profile options](vpn-auto-trigger-profile.md) - [VPN security features](vpn-security-features.md) diff --git a/windows/keep-secure/vpn-guide.md b/windows/keep-secure/vpn-guide.md index 7914168eeb..cef2464051 100644 --- a/windows/keep-secure/vpn-guide.md +++ b/windows/keep-secure/vpn-guide.md @@ -29,9 +29,8 @@ This guide will walk you through the decisions you will make for Windows 10 clie | --- | --- | | [VPN connection types](vpn-connection-type.md) | Select a VPN client and tunneling protocol | | [VPN routing decisions](vpn-routing.md) | Choose beetween split tunnel and force tunnel configuration | -| [VPN authentication options](vpn-authentication.md) | how to authenticate VPN connection: EAP-based, (?) | -| [VPN and conditional access](vpn-conditional-access.md) | use Azure Active Directory policy evaluation to set access policies for VPN | -| [VPN proxy settings](vpn-proxy-settings.md) | | +| [VPN authentication options](vpn-authentication.md) | Select a method for Extensible Authentication Protocol (EAP) authentication. | +| [VPN and conditional access](vpn-conditional-access.md) | Use Azure Active Directory policy evaluation to set access policies for VPN connections. | | [VPN name resolution](vpn-name-resolution.md) | how name resolution should happen | | [VPN auto-triggered profile options](vpn-auto-trigger-profile.md) | auto-connect clients to VPN: app-triggered, name-based trigger, "always on", trusted network detection | | [VPN security features](vpn-security-features.md) | lockdown, traffic filtering, WIP | diff --git a/windows/keep-secure/vpn-name-resolution.md b/windows/keep-secure/vpn-name-resolution.md index 9d73b9faa4..68db0e48c1 100644 --- a/windows/keep-secure/vpn-name-resolution.md +++ b/windows/keep-secure/vpn-name-resolution.md @@ -22,7 +22,6 @@ localizationpriority: high - [VPN routing decisions](vpn-routing.md) - [VPN authentication options](vpn-authentication.md) - [VPN and conditional access](vpn-conditional-access.md) -- [VPN proxy settings](vpn-proxy-settings.md) - [VPN auto-triggered profile options](vpn-auto-trigger-profile.md) - [VPN security features](vpn-security-features.md) - [VPN profile options](vpn-profile-options.md) \ No newline at end of file diff --git a/windows/keep-secure/vpn-profile-options.md b/windows/keep-secure/vpn-profile-options.md index 1a19b83480..e56cf8f0b0 100644 --- a/windows/keep-secure/vpn-profile-options.md +++ b/windows/keep-secure/vpn-profile-options.md @@ -72,7 +72,6 @@ A VPN profile configured with LockDown secures the device to only allow network - [VPN routing decisions](vpn-routing.md) - [VPN authentication options](vpn-authentication.md) - [VPN and conditional access](vpn-conditional-access.md) -- [VPN proxy settings](vpn-proxy-settings.md) - [VPN name resolution](vpn-name-resolution.md) - [VPN auto-triggered profile options](vpn-auto-trigger-profile.md) - [VPN security features](vpn-security-features.md) diff --git a/windows/keep-secure/vpn-proxy-settings.md b/windows/keep-secure/vpn-proxy-settings.md index 9dcad69218..dfdc32ba3d 100644 --- a/windows/keep-secure/vpn-proxy-settings.md +++ b/windows/keep-secure/vpn-proxy-settings.md @@ -15,6 +15,14 @@ localizationpriority: high - Windows 10 - Windows 10 Mobile + +If your organization uses a proxy, especially in the case of force tunneled VPN, you can add an Interface Specific proxy with VPN. This can be configured using the MDM/SCCM configuration where you can provide either a Proxy auto-config (PAC) or Web Proxy Autodiscovery Protocol (WPAD) file, or specify a server and port. + +**Bypass proxy settings for local addresses** is not currently supported. + + + + ## Related topics - [VPN technical guide](vpn-guide.md) diff --git a/windows/keep-secure/vpn-routing.md b/windows/keep-secure/vpn-routing.md index 46e89c359e..215bae3fe1 100644 --- a/windows/keep-secure/vpn-routing.md +++ b/windows/keep-secure/vpn-routing.md @@ -61,7 +61,6 @@ Next, in **Corporate Boundaries**, you add the routes that should use the VPN co - [VPN connection types](vpn-connection-type.md) - [VPN authentication options](vpn-authentication.md) - [VPN and conditional access](vpn-conditional-access.md) -- [VPN proxy settings](vpn-proxy-settings.md) - [VPN name resolution](vpn-name-resolution.md) - [VPN auto-triggered profile options](vpn-auto-trigger-profile.md) - [VPN security features](vpn-security-features.md) diff --git a/windows/keep-secure/vpn-security-features.md b/windows/keep-secure/vpn-security-features.md index ae814ae70a..d6342a7305 100644 --- a/windows/keep-secure/vpn-security-features.md +++ b/windows/keep-secure/vpn-security-features.md @@ -22,7 +22,6 @@ localizationpriority: high - [VPN routing decisions](vpn-routing.md) - [VPN authentication options](vpn-authentication.md) - [VPN and conditional access](vpn-conditional-access.md) -- [VPN proxy settings](vpn-proxy-settings.md) - [VPN name resolution](vpn-name-resolution.md) - [VPN auto-triggered profile options](vpn-auto-trigger-profile.md) - [VPN profile options](vpn-profile-options.md) \ No newline at end of file