A global workforce at Contoso uses Windows, macOS, and Linux laptops. The security team requires Azure AD-based authentication (so Conditional Access and MFA are enforced) for Point-to-Site VPN. Which authentication method should you choose, and what is a reason you would choose certificate authentication instead?
Choose an answer
Tap an option to check your answer.
Correct answer: Choose Azure AD authentication because it enables Conditional Access and MFA. Choose certificate authentication instead if you must support older OS clients that do not have OpenVPN or IKEv2 support or if centralized user identity is not desired..
Why this is the answer
Azure AD authentication is the correct choice because it natively integrates with Azure AD Conditional Access and Multi-Factor Authentication (MFA), fulfilling the security team's requirements for a global workforce using diverse operating systems. This method leverages OpenVPN and IKEv2 protocols, which are widely supported on modern Windows, macOS, and Linux clients. Certificate authentication would be chosen instead if there's a need to support very old operating systems or clients that lack OpenVPN/IKEv2 support, or if an organization prefers not to centralize user identity management through Azure AD. The other options are incorrect because certificate authentication does not inherently enable Conditional Access/MFA, Azure AD authentication does not support legacy VPN protocols like SSTP/IKEv1/PPTP for P2S, and certificate authentication is not the only method supporting macOS/Linux for P2S VPN.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed