We are mostly cloud-based but still have a legacy on-premises service that staff need to access for things such as terminal services, network drives, printers, and directory-integrated applications. Previously, users logged into their laptops with a password and then enabled a firewall-hosted VPN client. The VPN credential was provisioned through a one-time invitation and associated with the user's identity account, with the device storing the necessary credential securely.
An assessor raised concerns that this setup effectively allows the external service to be accessed using only something the user knows, and suggested that multifactor authentication may be required for VPN connections. I'm trying to understand what authentication sequence other organizations use, including whether MFA is performed every time the VPN connects, periodically, or only when the device or user is initially enrolled.
How do always-on VPN deployments handle this? Would device certificates stored in a TPM, password or biometric laptop login, periodic identity-provider reauthentication, or MFA at the individual application level satisfy the security requirement?
5 Answers
A device certificate stored in the TPM can prove that the connection is coming from an enrolled, managed device. It is often combined with a user password, biometric, or identity-provider authentication. That addresses device trust, but it does not necessarily replace MFA for the user, especially where policy requires two independent factors.
Another design is to minimize what the VPN exposes. Use the tunnel for connectivity or service discovery, while each application still requires strong authentication and authorization. In a zero-trust model, gaining network access alone does not grant access to file shares, remote desktops, or administrative services. For some organizations, replacing broad network VPN access with application-specific access is simpler and safer.
For internal wired and wireless access, 802.1X with certificates is another pattern. The same managed-device certificate can authenticate the device across network connections, while user identity and application controls provide the additional authorization layer. The exact requirement depends on the assessor’s interpretation and the organization’s risk assessment, so the written control and session policy matter as much as the VPN product.
A common approach is an always-on access client tied to the identity provider. The user signs into the laptop with a password or biometric, and the client uses the device and user identity to provide access. Periodic reauthentication is still required, with the frequency and MFA requirements based on policy, risk, and sometimes the user’s location. The VPN connection itself should not automatically be treated as authorization to every internal service.
Some environments use a more explicit sequence: sign into the laptop, open the VPN client, complete identity-provider authentication and MFA, then connect to the required desktop or application. Sessions may be limited to a fixed period such as 12 hours, after which the user must authenticate again. This is more cumbersome, but it makes the authentication event and session lifetime clear.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures