An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
Welcome to Microsoft Q&A
Hello @Brandon Boudreaux , I hope you are doing well,
Does this affect Windows 365 Cloud PCs? No, this root certificate rotation does not affect your Windows 365 Cloud PCs or their underlying connectivity.
Windows 365 utilizes an Azure Network Connection (ANC) to inject the Cloud PC's virtual NIC directly into your customer-managed Azure VNet. Once inside the VNet, the Cloud PC relies on native Azure routing, VNet Peering, or Site-to-Site (S2S) VPN / ExpressRoute connections to reach your internal resources.
Windows 365 Cloud PCs do not run or rely on Point-to-Site (P2S) VPN Client Profiles for their backend Azure integration. The notification you received is strictly for physical endpoints (like a user's local Windows laptop or Mac) that have the Azure VPN Client software installed and actively dial into your Azure VPN Gateway.
What is left for the Azure Admin to do?
For W365 Cloud PCs: Absolutely nothing. The Azure backend and your VNet handle this seamlessly.
- For physical remote workers: If you have actual users working from home on physical laptops who use the Azure VPN Client to dial into your network, you must generate a new VPN profile from the Azure Portal and push it to their laptops via Intune or manual installation before January 2027.
😊 If my answer helped you resolve your issue, please consider marking it as the correct answer. This helps others in the community find solutions more easily. Thanks!