Skip to content

Distributing profiles through Group Policy

On domain-joined Windows computers, the profile can be delivered when the employee signs in, without requiring them to import it.

  • The gateway is connected to Active Directory. See Connecting Active Directory.
  • The gateway runs on a domain-joined Windows Server. Automatic distribution from a gateway running on Linux requires additional configuration. For details, contact us. Without this configuration, profiles are distributed from the console.
  • The latest version of the nuVPN app for Windows is installed on the computers.
  • At the first sign-in, the computer is on the internal network and can communicate with the gateway.
  1. Download the logon script

    In the console, under Profile distribution, select Group Policy and download the sample logon script.

  2. Create a policy

    In Group Policy Management, create a policy and link it to the OU containing the users who will have VPN access.

  3. Add the script

    Under User Configuration › Policies › Windows Settings › Scripts (Logon), add the script as a PowerShell script.

  4. Test on one computer

    Sign in to a computer with a user account from the access group and open the nuVPN app. The profile should appear in the app.

  • Each employee has one device per computer. Signing in again does not create a duplicate device.
  • A new profile for the same employee on the same computer is created only after the previous profile is revoked in the console.
  • On Mac, phones, and computers that are not joined to the domain, profiles are distributed from the console. See Adding people without a directory.