Microsoft has recently issued a service advisory to IT administrators, confirming that on some Windows 11 devices, Always On VPN may fail to connect properly after installing the September 2026 update. The affected VPN configurations typically enable automatic protocol selection, switching from IKEv2 to SSTP once the IKEv2 connection fails, or attempting the reverse. Microsoft published the full advisory on its Windows release health dashboard.
What Always On VPN Is
This is Microsoft’s automatic encrypted tunnel connection built for enterprise users. Some companies demand a higher standard of security, so employees typically must connect to the corporate VPN before entering the internal network and using related services. Once configured, Always On VPN automatically establishes the encrypted tunnel every time the device starts, requiring no manual action from the user.
IT administrators can also split traffic on the server by app and service, a capability also used for domain-joined devices, non-domain-joined devices, and Microsoft Entra ID-joined devices. For enterprise users, once this feature malfunctions, they cannot connect to the company’s internal network, which can disrupt everyday work.
IT Administrators Must Manually Adjust the Protocol
The problem currently affecting Always On VPN is that, due to the abnormal protocol switch, the connection remains stuck in a “Connecting” state and keeps retrying endlessly, after which an error appears stating that the specified port is already in use. According to Microsoft’s investigation, when automatic protocol selection fails on the first attempt and then retries, the connection resources may fail to release, which ultimately triggers the “port already in use” message.
Microsoft’s temporary solution is for IT administrators to change the Always On VPN configuration from automatic protocol selection to a fixed IKEv2 or SSTP protocol, depending on the enterprise’s internal network environment, security requirements, and existing deployment. Before making the change, administrators should confirm that the VPN gateway, certificate authentication, multi-factor authentication, and client policies all support the chosen protocol.
Support Our Threat Intelligence
Find our tech and OS security coverage helpful? Support our work today and unlock a 100% ad-free reading experience!