The new KB did not resolve the problem for us either. Although our issue may be different. Here's how we set it up and what happens.
We create the VPN a little differently so that people can sign in to the VPN BEFORE signing in to the computer. The option will show as a new icon on the bottom left of the login screen AFTER pressing Ctl-Alt-Del. Click it and you will see a new sign on
box for your VPN credentials. Benefit of this is GPs all execute just like normal along with login scripts.
1: Go to Network & Internet
2: Click on Dial-Up
3: Setup a New Connection
4: Connect to a Workplace
5: Create a New Connection
6: Use my Internet Connection (VPN)
7: Enter the address for your VPN
8: Give it a name
9: Check the box for Allow other people to use this connection. (This is what makes it work prior to logging on to the machine itself)
10: Click Create
11: Click Change Adapter Options (top right of window, stretch it out if you have to)
12: Right click on the adapter for your new Connection. Select Properties
13: Verify VPN address on the General tab
14: Select Security tab
15: Set proper type of VPN, for us this is Layer 2 Tunneling Protocol with IPsec (L2TP/IPsec) (We use the Meraki VPN)
16: Set the proper encryption, for us this is "Require encryption (disconnect if server declines)
17: Set the Radio button for "Allow These Protocols", then set Unencrypted password (PAP) NOTE: This IS encrypted. Very misleading.
18: Click on Advanced Settings
19: Set Radio button for "Use preshared key for authentication" and then enter your preshared key stored in your VPN server/router
20: Ok, close it all up.
For us this works one time. After the first use, if you use an IP for the VPN address it will be corrupted. Additionally, the Pre-Shared key will be gone and "Use certificate for authentication" will be selected. This nonsense has gone
on now since 1809. It's a CLUSTER! Fix it Microsoft!!