I’m excited to announce that I’ll be attending the upcoming Live! 360 Event, November 15-20, 2026, at Royal Pacific Resort at Universal Orlando, Florida. I’ll be in attendance all week and will be delivering a few talks at the event this year.
Sessions
I’ll be presenting two sessions at this year’s event. They are:
TMH06 – Moving to Zero Trust: Entra Private Access for Always On VPN Administrators. This is a popular session demonstrating how to migrate from Always On VPN (or any other VPN solution) to Entra Private Access with Zero Trust enforcement. I’ll describe how to get “from here to there,” moving from fully open VPN access to strict zero trust access without disruption.
Join Me!
If you are planning to attend the event, please join my sessions! I will be at the conference center all week, so don’t hesitate to reach out and contact me while you are there. I’m looking forward to seeing everyone soon!
Microsoft released the September 2026 security updates today, which include numerous fixes affecting Always On VPN deployments. This month’s edition addresses vulnerabilities in Windows Server Routing and Remote Access (RRAS), VPN protocols such as Secure Socket Tunneling Protocol (SSTP) and Internet Key Exchange version 2 (IKEv2). The updates also include Active Directory Certificate Services (AD CS), a crucial supporting infrastructure service for Always On VPN.
RRAS
September 2026 Microsoft security updates include 8 CVEs for RRAS. Four are rated Critical, the most severe having a CVSS rating of 9.8.
RCEs
The following four CVEs are Remote Code Execution vulnerabilities. All are rated critical.
Microsoft AD CS is commonly deployed to issue and manage certificates used for encryption and user and device authentication in Always On VPN deployments. The following four CVEs address vulnerabilities disclosed in AD CS. The first two are privilege escalation vulnerabilities, the third covers information disclosure, and the last addresses a tampering vulnerability. All are rated Important.
The September 2026 Microsoft security updates address several critical vulnerabilities affecting organizations that have deployed Microsoft Always On VPN. Administrators are encouraged to update their systems as soon as possible.
The Microsoft Entra Private Network Connector is a lightweight on-premises software agent that enables Microsoft Entra Private Access to forward Global Secure Access (GSA) client traffic to internal resources. In environments with multiple connectors, traffic is normally distributed across available connectors in a connector group. While this improves resiliency and load distribution, it can create challenges for applications that rely on a consistent connector source IP address.
Stateless Connectors
By default, requests are distributed randomly among the available connectors in a connector group. Traffic forwarded to the internal resource uses the connector server’s IP address as its source. Consequently, separate connections from the same user and device can reach the application through different connectors. Importantly, session state is not shared among connectors in a connector group. As such, applications that associate session state with the source IP address may reject or interrupt these connections.
Why Session Persistence Matters
In some scenarios, an internal application might allow access only from specific connector IP addresses or associate an authenticated session with the source IP address. Random connector selection can cause subsequent connections to arrive from a different address, potentially interrupting the session. Session persistence reduces this risk by consistently using the same connector for the user and device.
Session Persistence
Microsoft recently introduced session persistence for Entra Private Access applications. When enabled, requests from the same user and device are consistently routed to the same connector for the duration of the session. This helps maintain a consistent connector egress IP address for applications that depend on source IP addresses for authentication, authorization, or session management.
Traffic Routing
The connector traffic routing method is configured on a per-application basis. Traffic routing methods can be defined on Quick Access or Enterprise applications, and the setting can be configured on the Network access properties tab. Administrators have two options: Random or Session Persistence.
Random
This is the default behavior for the Private Network connector. All new connections are distributed randomly among connectors in the connector group.
Session Persistence
Selecting the Session Persistence option consistently routes requests from the same user and device to the connector on which the session was established.
Connector Routing Method Comparison
The following table summarizes these configuration options.
Routing Method
Benefits
Considerations
Random
Better distribution across connectors in a connector group
Source IP address may change between connections
Session Persistence
Consistent connector egress IP address
May not distribute sessions as evenly as the Random method
Failover
If the preferred connector becomes unavailable, subsequent traffic may be routed through another available connector. Applications that depend on the connector’s source IP address might require the user to establish a new session.
GSA Applications Only
Session persistence applies only to Global Secure Access applications. It is not supported for applications published using Microsoft Entra Application Proxy.
Summary
By default, Microsoft Entra Private Access distributes requests randomly among available connectors. Although this provides load distribution, it can create problems for applications that depend on a consistent connector source IP address. Session persistence addresses this issue by consistently routing traffic from the same user and device through the same connector for the duration of the session. This feature applies only to Global Secure Access applications and is not supported for Microsoft Entra Application Proxy applications.