Microsoft Always-On VPN - United States (2024)

Microsoft Always-On VPN - United States (1)

James Kindon - 09.04.2020

Many of our recent engagements involve a modernisation of deploying and managing Windows 10 PCs, with Microsoft Intune and System Center Configuration Manager. In part, these projects are driven by the customer’s desire to reduce the number of vendors they deal with, alongside a more strategic move to reduce their infrastructure required to manage end-point devices.

These customer’s users are typically more mobile than they were 5-10 years ago and are often working from home or other remote locations, so the ability to consistently manage devices regardless of location is a key requirement. While we are a certainly seeing an uptake in mobility, customers still have legacy applications with data locked into on-premises data centers they need to manage and ensure their users continue to have access to.

Access gaps are often met with the use of application delivery solutions such as Citrix Virtual Apps and Desktops and Microsoft Remote Desktop Services or by any number of 3rd party firewall-based VPN solutions with secure tunnels back into the juicy innards of the corporate data center.

Microsoft provided us with a great, yet challenging solution in the form of DirectAccess – an extremely smooth solution for the Microsoft ecosystem which would poll a web service to identify internal vs external locations and establish a seamless VPN connection once outside the perimeter without user intervention. This was a robust solution, which whilst simple for the user, was typically quite complex for admins. DirectAccess used a combination of Windows Server, IPv6 Teredo tunnelling and a heavy amount of configuration to get things running smoothly. It was very much a “get it working and don’t touch it” solution that served its purpose.

With the release of Windows 10 1607, Microsoft now recommends Always On VPN in preference to DirectAccess. The beauty of this solution is its simplicity and ease of deployment, integrating cleanly with SCCM, PowerShell and Microsoft Intune. It has enhanced smarts around network detection tunnel triggers, allowing for the ability to use both user and device layer tunnels for remote management and inbound initiated connections, as well as application driven VPN tunnels (commonly known as MicroVPNs). The usual suspects around VPN capabilities are addressed, with both split tunnel and full tunnel configurations available. Traffic filtering and security are also natively available in Always On VPN.

Microsoft Always-On VPN - United States (3)

If you are an existing Direct Access customer, then it’s worth investigating whether Always-On VPN addresses all of your Remote Access requirements. A mapping of features and functionality is provided by Microsoft.

What’s fun about this solution is it’s built upon yet another Microsoft revived technology: Routing and Remote Access (who remembers RRAS?). The same technology underpins many of Microsoft Azure VPN tunnels and offers a very familiar interface for those admins who have been working with Windows for a while. If you understand RRAS then Always-On VPN will be a walk in the park.

The solution comes at no cost and is built into all supported flavours of Windows 10. Which means there are no additional VPN clients that need to be deployed, reducing PC management complexity. Additionally,Always-On VPN supports Azure AD Conditional Access and MFA for an extra layer of security. The ability to prevent access to the VPN unless the Windows device is compliant is an ideal way to ensure only approved and secure devices are making tunnel connections into your data center.

Always-On VPN is quick and easy to deploy, offers a high level of encryption and security, and fills a void which still exists in the modern workplace. Leveraging an internal Active Directory Domain Services environment, internal Active Directory Certificate Services Authority, and simple DMZ architecture, Always-On VPN typically goes off like wildfire once introduced to an organization with an extremely high level of user satisfaction to boot.

Microsoft recently migrated their entire internal fleet to Always-On VPN, a showcase article has been written to describe the success Microsoft IT had in the deployment.

Routing and Remote Access-based VPN solutions have typically had a challenge with load balancing and high availability, however with the introduction of low cost solutions like Azure Traffic Manager, multi-site Active-Active deployments are a walk in the park

Looking at your Windows 10 upgrades, deployments or modernisation with Intune and still have requirements for network connectivity back to your corporate locations? Always-On VPN should be the first discussion for VPN connectivity.

THANK YOU FOR YOUR SUBMISSION!

Microsoft Always-On VPN - United States (4)

The form was submitted successfully.

Join the Insentra Community with the Insentragram Newsletter

Hungry for more?

IGEL Teams with Insentra and Insight to Help Western Health Improve Endpoint Management and Sustainability, Boost Security, and Enhance User Experience

IGEL’s integration with Imprivata makes it easy for the Australian healthcare provider to securely access Cerner’s electronic medical records (EMR) software and extend the life

Read More »

Removing Active Directory? Here’s What to Consider First

As organizations move legacy applications to cloud-based apps, they see the simplification of on-premises workloads to reduce cost. Active Directory (AD) is one of the

Read More »

IT Admin Nightmares: How to Survive the Biannual Security Audit Madness

Ladies and gentlemen, welcome to another episode of the IT Admin Nightmares! Today, we’re diving into the wild and often hair-pulling world of security audits,

Read More »

Microsoft Always-On VPN - United States (2024)
Top Articles
Latest Posts
Article information

Author: Delena Feil

Last Updated:

Views: 5654

Rating: 4.4 / 5 (45 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Delena Feil

Birthday: 1998-08-29

Address: 747 Lubowitz Run, Sidmouth, HI 90646-5543

Phone: +99513241752844

Job: Design Supervisor

Hobby: Digital arts, Lacemaking, Air sports, Running, Scouting, Shooting, Puzzles

Introduction: My name is Delena Feil, I am a clean, splendid, calm, fancy, jolly, bright, faithful person who loves writing and wants to share my knowledge and understanding with you.