Update windows/security/identity-protection/vpn/vpn-conditional-access.md

Co-authored-by: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
This commit is contained in:
msarcletti 2020-11-13 08:45:06 +01:00 committed by GitHub
parent 02c827d651
commit 776ea6eefc
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -74,7 +74,7 @@ Two client-side configuration service providers are leveraged for VPN device com
- Collects TPM data used to verify health states - Collects TPM data used to verify health states
- Forwards the data to the Health Attestation Service (HAS) - Forwards the data to the Health Attestation Service (HAS)
- Provisions the Health Attestation Certificate received from the HAS - Provisions the Health Attestation Certificate received from the HAS
- Upon request, forwards the Health Attestation Certificate (received from HAS) and related runtime information to the MDM server for verification - Upon request, forward the Health Attestation Certificate (received from HAS) and related runtime information to the MDM server for verification
> [!NOTE] > [!NOTE]
> Currently, it is required that certificates used for obtaining Kerberos tickets must be issued from an on-premises CA, and that SSO must be enabled in the users VPN profile. This will enable the user to access on-premises resources. > Currently, it is required that certificates used for obtaining Kerberos tickets must be issued from an on-premises CA, and that SSO must be enabled in the users VPN profile. This will enable the user to access on-premises resources.