Configure Personal Devices for Azure VPN without Intune enrollment

Melissa Ray 0 Reputation points
2025-01-05T12:41:30.5766667+00:00

We are migrating to Intune and transitioning all our Azure hybrid managed devices to Intune managed devices. Only corporate managed devices are enrolled in Intune, while personal devices are not accepted.

We operated without a domain controller and created new VPN. However, when attempting to connect to the new Azure VPN from new devices, an error occurs stating that the device can't be registered. Devices that previously connected to the old VPN can connect to the new VPN without issues.

It appears that the problem may be related to the policy against enrolling Intune devices, which we prefer to maintain. We provide users with the necessary steps to connect to the VPN, including software, XML configuration, and required certificates. All devices involved are running Windows 10.

Suggestions for resolving this issue would be greatly appreciated, as remote work functionality is essential for us. Thank you for any assistance!

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,985 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,476 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Crystal-MSFT 51,226 Reputation points Microsoft Vendor
    2025-01-06T01:57:44.81+00:00

    @Melissa Ray, Thanks for posting in Q&A. From your description, I know we set Intune enrollment policy to block personal device. For the new devices, when it connects to new Azure VPN, it is asked to register the device. Based as I know, For Windows device which join type is Microsoft Entra registered, it is considered as personal device. This can be the reason which it is blocked I think.

    If this is a corporate managed device. You can firstly enroll it into Intune as corporate device to make it as Microsoft Entra joined type in Microsoft Entra ID. Then try to connect the new Azure VPN to see if it works.

    https://learn.microsoft.com/en-us/mem/intune/fundamentals/deployment-guide-enrollment-windows

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Melissa Ray 0 Reputation points
    2025-01-15T13:06:26.59+00:00

    Hello! I'm very sorry for the late reply, I was sick. Thank you for helping!

    corporate devices are enrolled just fine, the problem is the employees' personal laptops or devices, which we don't enroll to Intune. I am not sure what can be done to fix it but thank you for the explanation for why it might not be working right now. Any help on making it work despite not enrolling the employees' devices (used soley to enter the VPN to work from home) will be gladly appreciated.

    Have a good day!


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.