Für Always-ON-VPN wird Intune oder SCCM benötigt

z.B. M365 Business Premium

User bekommt passende Lizenz:

image-100 Intune: How to: Always-On-VPN

Aktivierung der MDM Funktion in Azure AD:

image-101 Intune: How to: Always-On-VPN
image-102-1024x697 Intune: How to: Always-On-VPN

Client verbinden mit Azure AD:

image-114 Intune: How to: Always-On-VPN

Client nun verwaltet in Intune:

image-103-1024x579 Intune: How to: Always-On-VPN
image-105-1024x470 Intune: How to: Always-On-VPN
image-106 Intune: How to: Always-On-VPN
image-107 Intune: How to: Always-On-VPN
image-108 Intune: How to: Always-On-VPN
image-110-1024x693 Intune: How to: Always-On-VPN
image-110-1024x693 Intune: How to: Always-On-VPN
image-109 Intune: How to: Always-On-VPN
image-112 Intune: How to: Always-On-VPN
image-111 Intune: How to: Always-On-VPN
image-113 Intune: How to: Always-On-VPN

Powershell-Befehl dür die EAP XML Generierung

$a = Get-VpnConnection -Name Test
$a.EapConfigXmlStream.InnerXml