# Controlling user access via Azure AD groups

**URL:** https://forum.pritunl.com/t/controlling-user-access-via-azure-ad-groups/255
**Category:** Pritunl VPN
**Created:** [July 20, 2022, 12:45am UTC](https://forum.pritunl.com/t/controlling-user-access-via-azure-ad-groups/255 "2022-07-20T00:45:26Z")
**Posts on this page:** 1
**Showing post:** 4

<div class="post-metadata">

### Author: ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)
#### Post date: [July 25, 2022, 1:57am UTC](https://forum.pritunl.com/t/controlling-user-access-via-azure-ad-groups/255/4 "2022-07-25T01:57:56Z")

</div>

The Azure API is used for every VPN connection, disabled or deleted users in Azure cannot connect. The groups mode can be used to also validate the user groups on each connection. The certificate is sufficient for authenticating the user to the VPN server. This design is required to maintain compatibility with all OpenVPN clients. There’s several multi-factor authentication options that will provide additional authentication for connections.

---

_[View the full topic](https://forum.pritunl.com/t/controlling-user-access-via-azure-ad-groups/255)._
