Intune Deployment of US Azure VPN and Configuration
As of 7/11/2025:
Installing the Azure VPN Client as well as the vpn configuration can be done automatically via intune and entra groups. Intune will push these out usually within 30 minutes. These can also be manually installed/uploaded as well.
- Go to the user in either entra or 365 admin center and click on “Manage Groups” under their account.
- Assign membership to both the “(Intune) Azure VPN Client” and “(Azure VPN) US Buffalo Watchguard Migration Group”.
- Note: The Watchguard Migration group is just a catch-all group we are using for now. We will eventually be using more detailed/granular groups.


- Assign them and wait approximately 30 minutes for them to install.
Once they are installed the user should see a new vpn configuration titled “Kee Safety US VPN” even if they are in a different BU. The vpn will work the same for everyone.
They can either connect to the vpn via the azure client or through the built-in windows client. The initial connection must be made with the Azure client as it will prompt them to sign in with their Microsoft credentials. If there is a second authentication request being made, they can close that, it is a bug, they just need to sign in the first time. After the initial connection, they should be able to use the built-in windows vpn client which is recommended.
Should the client install but not the vpn configuration, it can be uploaded manually.
- Grab the .xml file for the NA IT Support group chat in teams.
-
Go to the + sign in the Azure VPN client and click “Import”.

- Upload the .xml file.
They should successfully have both the client and vpn configuration on their pc now.
Note: Again, this “US Buffalo Watchguard Migration Group” is a temporary solution that will be removed eventually. This is a catch-all group that should allow access to anything. Anything a user cannot access should be notified to Justin or Charles.