Azure VPN client error 628 after changing from sstp to IKEv2

Arnaud Henry-Lefort 0 Reputation points
2026-09-28T21:08:29.9+00:00

Hello,

I make the mistake to convert the sstp to IKEv2 and now I can't make it work. We use point to site from our Azure VM to our employee WFH.

I checked certificate, deleted the VPN on client machine and reinstall the latest, delete the gateway and rebuild it but still the same issue.

We use basic SKU and have 2 users atm.

This is the message on client machine: "The connection was terminated by the remote computer before it could be completed. (Error 628) For customised troubleshooting information for this connection, click Help."

The error come after few second of the step: "verifying password for xxx"

Can someone help ? I run out of option and we desperately need the VPN to work to allow people to connect to our data.

Kind regards

Azure VPN Gateway
Azure VPN Gateway

An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.

0 comments No comments

1 answer

Sort by: Newest
  1. Divyesh Govaerdhanan 11,890 Reputation points MVP Volunteer Moderator
    2026-09-28T22:10:46.1033333+00:00

    Hello Arnaud Henry-Lefort,

    Welcome to Microsoft Q&A,

    Error 628 right after "verifying password" usually means the client is still using the old SSTP profile settings against a gateway now expecting IKEv2 certificate authentication. A few things to check.

    1. Basic SKU only started supporting IKEv2 in November 2025, and the switch needs to be done properly, not just toggled. In the portal, go to your VPN gateway > Point-to-site configuration > Tunnel type, and set it to IKEv2 and SSTP (SSL), then Save. Or via PowerShell:
    $vng = Get-AzVirtualNetworkGateway -Name <gwName> -ResourceGroupName <rgName>
    $VpnClientRootCert = New-AzVpnClientRootCertificate -Name "RootCert" -PublicCertData <PublicCertData>
    Set-AzVirtualNetworkGateway -VirtualNetworkGateway $vng -VpnClientAddressPool <AddressPool> -VpnClientProtocol IkeV2,SSTP -VpnAuthenticationType Certificate -VpnClientRootCertificates $VpnClientRootCert
    
    1. This is the step most people miss: after changing the tunnel type, you must download the VPN client configuration package again and reinstall it on every client machine. The old package still points to the SSTP settings, so reinstalling just the Azure VPN Client app (without the new profile) will keep failing.
    2. Basic SKU does not support RADIUS or Entra ID authentication for point-to-site, only certificate-based. Confirm the same root certificate you uploaded to the gateway is the one installed on the client, and that the client cert used to connect was issued from that same root.

    Full migration steps: SSTP protocol retirement and connections migration

    Please click Accept Answer and upvote if this helped.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.