mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-13 13:57:22 +00:00
Merge pull request #8843 from PeterSmithRedmond/patch-8
Move "lockdown" security info to the bottom
This commit is contained in:
commit
8c7dc1ea0c
@ -20,23 +20,6 @@ ms.author: dansimp
|
||||
- Windows 10 Mobile
|
||||
|
||||
|
||||
## LockDown VPN
|
||||
|
||||
A VPN profile configured with LockDown secures the device to only allow network traffic over the VPN interface. It has the following features:
|
||||
|
||||
- The system attempts to keep the VPN connected at all times.
|
||||
- The user cannot disconnect the VPN connection.
|
||||
- The user cannot delete or modify the VPN profile.
|
||||
- The VPN LockDown profile uses forced tunnel connection.
|
||||
- If the VPN connection is not available, outbound network traffic is blocked.
|
||||
- Only one VPN LockDown profile is allowed on a device.
|
||||
|
||||
> [!NOTE]
|
||||
> For built-in VPN, LockDown VPN is only available for the Internet Key Exchange version 2 (IKEv2) connection type.
|
||||
|
||||
Deploy this feature with caution, as the resultant connection will not be able to send or receive any network traffic without the VPN being connected.
|
||||
|
||||
|
||||
## Windows Information Protection (WIP) integration with VPN
|
||||
|
||||
Windows Information Protection provides capabilities allowing the separation and protection of enterprise data against disclosure across both company and personally owned devices, without requiring additional changes to the environments or the apps themselves. Additionally, when used with Rights Management Services (RMS), WIP can help to protect enterprise data locally.
|
||||
@ -78,6 +61,24 @@ The following image shows the interface to configure traffic rules in a VPN Prof
|
||||
|
||||

|
||||
|
||||
|
||||
## LockDown VPN
|
||||
|
||||
A VPN profile configured with LockDown secures the device to only allow network traffic over the VPN interface. It has the following features:
|
||||
|
||||
- The system attempts to keep the VPN connected at all times.
|
||||
- The user cannot disconnect the VPN connection.
|
||||
- The user cannot delete or modify the VPN profile.
|
||||
- The VPN LockDown profile uses forced tunnel connection.
|
||||
- If the VPN connection is not available, outbound network traffic is blocked.
|
||||
- Only one VPN LockDown profile is allowed on a device.
|
||||
|
||||
> [!NOTE]
|
||||
> For built-in VPN, LockDown VPN is only available for the Internet Key Exchange version 2 (IKEv2) connection type.
|
||||
|
||||
Deploy this feature with caution, as the resultant connection will not be able to send or receive any network traffic without the VPN being connected.
|
||||
|
||||
|
||||
## Related topics
|
||||
|
||||
- [VPN technical guide](vpn-guide.md)
|
||||
|
Loading…
x
Reference in New Issue
Block a user