Azure VPN Gateway root certificate rotation affecting Windows 365 Cloud PC

Brandon Boudreaux 20 Reputation points
2026-06-17T15:24:13.65+00:00

We received the notification "Update your Azure VPN Gateway Point-to-Site VPN client profile before 31 January 2027". Does the Azure VPN Gateway root certificate rotation affect Windows 365 Cloud PC connectivity in this case? As this is all used by Azure on the back end, is there anything that still needs to be done by the Azure admin?

Azure VPN Gateway
Azure VPN Gateway

An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.


Answer accepted by question author
Jose Benjamin Solis Nolasco 12,606 Reputation points Volunteer Moderator
2026-06-17T20:32:15.75+00:00

Welcome to Microsoft Q&A

Hello @Brandon Boudreaux , I hope you are doing well,

Does this affect Windows 365 Cloud PCs? No, this root certificate rotation does not affect your Windows 365 Cloud PCs or their underlying connectivity.

Windows 365 utilizes an Azure Network Connection (ANC) to inject the Cloud PC's virtual NIC directly into your customer-managed Azure VNet. Once inside the VNet, the Cloud PC relies on native Azure routing, VNet Peering, or Site-to-Site (S2S) VPN / ExpressRoute connections to reach your internal resources.

Windows 365 Cloud PCs do not run or rely on Point-to-Site (P2S) VPN Client Profiles for their backend Azure integration. The notification you received is strictly for physical endpoints (like a user's local Windows laptop or Mac) that have the Azure VPN Client software installed and actively dial into your Azure VPN Gateway.

What is left for the Azure Admin to do?

For W365 Cloud PCs: Absolutely nothing. The Azure backend and your VNet handle this seamlessly.

  • For physical remote workers: If you have actual users working from home on physical laptops who use the Azure VPN Client to dial into your network, you must generate a new VPN profile from the Azure Portal and push it to their laptops via Intune or manual installation before January 2027.

😊 If my answer helped you resolve your issue, please consider marking it as the correct answer. This helps others in the community find solutions more easily. Thanks!

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Newest
  1. AI answer

    2026-06-17T15:24:23.54+00:00

    The Azure VPN Gateway root certificate rotation affects all Point-to-Site (P2S) VPN clients that connect through the affected gateway. This includes any Cloud PCs or other resources that rely on that P2S gateway profile for connectivity.

    Microsoft rotates the gateway root certificate on the backend, but Azure administrators must still generate and redistribute an updated P2S VPN client profile before the migration deadline. If the profile is not updated, P2S connections that use the old profile will fail after the gateway switches fully to the new root certificate.

    The rotation does not change the VPN gateway configuration (tunnel type, authentication method, address pool, routing). Only the client profile needs to be updated. The updated profile contains the new root certificate information required to establish trust with the gateway after migration.

    Action required for the Azure admin:

    1. Confirm the gateway is listed in the Microsoft notification as affected.
    2. Generate a new P2S VPN client profile for the affected VPN gateway.
    3. Distribute the updated profile to all P2S users/clients that connect through that gateway (including any Cloud PC scenarios that depend on it).

    If the updated profile is not installed on the clients by the deadline, those P2S connections will stop working once the old certificate is removed.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.