An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
Hello Arnaud Henry-Lefort,
Welcome to Microsoft Q&A,
Error 628 right after "verifying password" usually means the client is still using the old SSTP profile settings against a gateway now expecting IKEv2 certificate authentication. A few things to check.
- Basic SKU only started supporting IKEv2 in November 2025, and the switch needs to be done properly, not just toggled. In the portal, go to your VPN gateway > Point-to-site configuration > Tunnel type, and set it to IKEv2 and SSTP (SSL), then Save. Or via PowerShell:
$vng = Get-AzVirtualNetworkGateway -Name <gwName> -ResourceGroupName <rgName>
$VpnClientRootCert = New-AzVpnClientRootCertificate -Name "RootCert" -PublicCertData <PublicCertData>
Set-AzVirtualNetworkGateway -VirtualNetworkGateway $vng -VpnClientAddressPool <AddressPool> -VpnClientProtocol IkeV2,SSTP -VpnAuthenticationType Certificate -VpnClientRootCertificates $VpnClientRootCert
- This is the step most people miss: after changing the tunnel type, you must download the VPN client configuration package again and reinstall it on every client machine. The old package still points to the SSTP settings, so reinstalling just the Azure VPN Client app (without the new profile) will keep failing.
- Basic SKU does not support RADIUS or Entra ID authentication for point-to-site, only certificate-based. Confirm the same root certificate you uploaded to the gateway is the one installed on the client, and that the client cert used to connect was issued from that same root.
Full migration steps: SSTP protocol retirement and connections migration
Please click Accept Answer and upvote if this helped.