Hi everyone,
Has anyone found a solution for deploying a DNS suffix to clients using a Dial-Up IPsec VPN with IKEv2 and Entra SAML authentication?
We’re using Intune-deployed clients without admin rights. I’ve tried using post scripts, but they seem to fail due to permission restrictions. I also attempted to push the DNS suffix via the EMS server, but I still can’t get it to apply to IKEv2 VPN tunnels.
Does anyone have an idea or workaround to make this work?
Thanks in advance!
Turn on mode config and add the DNS suffix under internal-domain-list. No script needed. If you want to keep your files organized, I recommend cx file explorer for that.
I’ve run into this issue too — it’s tricky since IKEv2 tunnels don’t always inherit DNS suffixes cleanly, especially with Intune-managed, non-admin devices. One workaround is to push the suffix via Intune custom configuration profiles using PowerShell or OMA-URI settings before the VPN connects. Some admins also script it through Connection Manager profiles (CMAK) or apply it via a GPO that targets the VPN adapter once created. Would love to see if anyone’s found a cleaner Intune-only method though!
| User | Count |
|---|---|
| 2686 | |
| 1412 | |
| 810 | |
| 704 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.