# No automatic client reconnection with SSO authentication

**URL:** https://forum.pritunl.com/t/no-automatic-client-reconnection-with-sso-authentication/3781
**Category:** Pritunl VPN
**Tags:** pritunl-client, pritunl
**Created:** [April 21, 2026, 6:59am UTC](https://forum.pritunl.com/t/no-automatic-client-reconnection-with-sso-authentication/3781 "2026-04-21T06:59:18Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![ebu](https://forum.pritunl.com/letter_avatar_proxy/v4/letter/e/278dde/32.png) [@ebu](https://forum.pritunl.com/u/ebu)
#### Post date: [April 21, 2026, 6:59am UTC](https://forum.pritunl.com/t/no-automatic-client-reconnection-with-sso-authentication/3781/1 "2026-04-21T06:59:18Z")

</div>

Hello,  
We are currently looking at changing our Pritunl VPN servers from certificate-based authentication to Azure Entra SSO authentication.  
The configuration works without any issues, and we are able to authenticate successfully to the VPN using SSO.  
The problem we are facing is the following: previously, with certificate-based authentication, when we added a route on the server, we need to stop the pritunl server and start it after we added the route, all the clients reconnect automatically on the pritunl server. Even if the server was restarted, adding a route was barely noticeable for users.  
Now, with the SSO configuration, if I restart the server using the button in the web interface, I get the following messages on the client side:

- Connection timed out on Pritunl\_server\_name (username)
- Failed to authenticate to Pritunl\_server\_name (username)

After that, I am disconnected from my Pritunl client.  
I also tested with the ‘Pritunl Authentication Cache’ option enabled, but I observe the same behavior.

![image](https://forum-static.pritunl.com/original/2X/9/9c656195cf5aae90bc426ba0bc6a976026e70dce.png)

After this disconnection, I can reconnect without any issue by simply clicking the Connect button in the Pritunl client.  
My question is therefore: is it possible for clients to reconnect automatically when the SSO / Azure Entra authentication is enabled?

Thanks for your time and your work…

Eric

---

<div class="post-metadata">

### Author: ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)
#### Post date: [April 22, 2026, 3:40pm UTC](https://forum.pritunl.com/t/no-automatic-client-reconnection-with-sso-authentication/3781/2 "2026-04-22T15:40:08Z")

</div>

Check the logs in the top right of the server web console for the authentication failure reason. The cache token can expire and will not remain after the client system restarts.

---

<div class="post-metadata">

### Author: ![ebu](https://forum.pritunl.com/letter_avatar_proxy/v4/letter/e/278dde/32.png) [@ebu](https://forum.pritunl.com/u/ebu)
#### Post date: [April 27, 2026, 2:48pm UTC](https://forum.pritunl.com/t/no-automatic-client-reconnection-with-sso-authentication/3781/3 "2026-04-27T14:48:47Z")

</div>

> [@zach](#):
>
> logs in the top right of the server web console

Sorry for the delay, I had to run additional tests and noticed something strange.

When I click the Restart Server button (between Settings and Stop Server), I get the following message on the client:  
_Connection timed out on Pritunl\_server\_name (username)  
Failed to authenticate to Pritunl\_server\_name (username)_

> At the same time, I see these logs in the top-right corner of the web console:  
> [server\_name3][2026-04-27 14:21:14,128][INFO] Starting vpn server  
> server\_id = “”  
> instance\_id = “”  
> instances =   
> instances\_count = 0  
> route\_count = 3  
> network = “ipv4/16”  
> network6 = “ipv6/64”  
> ovpn\_dco = false  
> dynamic\_firewall = false  
> bypass\_sso\_auth = false  
> geo\_sort = false  
> force\_connect = false  
> sso\_auth = true  
> route\_dns = false  
> device\_auth = false  
> host\_id = “id\_server\_name3”  
> host\_address = “ip\_server\_name3”  
> host\_address6 = “ipv6\_server\_name3”  
> host\_networks = [“host\_network”]  
> cur\_timestamp = “2026-04-27 14:21:14.127797”  
> libipt = false  
> [server\_name3][2026-04-27 14:21:14,142][WARNING] Stopping duplicate instance, check date time sync  
> server\_id = “”  
> instance\_id = “69ef6f9d95cb03ff428a98a2”  
> [server\_name4][2026-04-27 14:21:14,275][INFO] Starting vpn server  
> server\_id = “”  
> instance\_id = “69ef70da342fde39bc6428fa”  
> instances = [{“instance\_id”: “”, “host\_id”: “id\_server\_name3”, “ping\_timestamp”: “2026-04-27 14:21:44.119000”}]  
> instances\_count = 1  
> route\_count = 3  
> network = “ipv4/16”  
> network6 = “ipv6/64”  
> ovpn\_dco = false  
> dynamic\_firewall = false  
> bypass\_sso\_auth = false  
> geo\_sort = false  
> force\_connect = false  
> sso\_auth = true  
> route\_dns = false  
> device\_auth = false  
> host\_id = “id\_server\_name4”  
> host\_address = “ip\_server\_name4”  
> host\_address6 = “ipv6\_server\_name4”  
> host\_networks = [“host\_network”]  
> cur\_timestamp = “2026-04-27 14:21:14.275010”  
> libipt = false  
> [server\_name4][2026-04-27 14:21:14,310][WARNING] Stopping duplicate instance, check date time sync  
> server\_id = “”  
> instance\_id = “69ef6f9d342fde39bc642072”  
> [server\_name3][2026-04-27 14:21:22,325][INFO] Authenticating user  
> user\_name = “username”  
> factors = [“azure”]

After this, the client never reconnects automatically.

If I manually click Connect in the Pritunl client, the following appears in the logs:

> [server\_name3][2026-04-27 14:22:19,204][INFO] Authenticating user  
> user\_name = “username”  
> factors = [“azure”]  
> [server\_name3][2026-04-27 14:22:19,213][INFO] Client authentication with sso token  
> user\_name = “username”  
> org\_name = “org\_name”  
> server\_name = “Pritunl\_server\_name”  
> [server\_name3][2026-04-27 14:22:19,214][INFO] Client sso authentication, skipping password  
> user\_name = “username”  
> org\_name = “org\_name”  
> server\_name = “Pritunl\_server\_name”  
> [server\_name3][2026-04-27 14:22:20,415][INFO] Storing authentication cache token  
> user\_name = “username”  
> factors = [“azure”]  
> [server\_name4][2026-04-27 14:22:21,303][INFO] Authenticating user  
> user\_name = “username”  
> factors = [“azure”]  
> [server\_name4][2026-04-27 14:22:21,309][INFO] Client authentication with sso token  
> user\_name = “username”  
> org\_name = “org\_name”  
> server\_name = “Pritunl\_server\_name”  
> [server\_name4][2026-04-27 14:22:21,310][INFO] Client sso authentication, skipping password  
> user\_name = “username”  
> org\_name = “org\_name”  
> server\_name = “Pritunl\_server\_name”

* * *

BUT, If I click Stop Server (between Restart Server and Delete Server), I only get this on the client:

_Connection timed out on Pritunl\_server\_name (username)_

The client status stays stuck on “Connecting”, and no logs appear at all in the web console.

When I click Start Server, the Pritunl client briefly shows:  
_Failed to connect to Pritunl\_server\_name (username)_  
However, immediately after that, the connection is actually successful.

Relevant logs:

> [server\_name4][2026-04-27 14:24:03,376][INFO] Starting vpn server  
> server\_id = “”  
> instance\_id = “”  
> instances =   
> instances\_count = 0  
> route\_count = 3  
> network = “ip/16”  
> network6 = “ipv6/64”  
> ovpn\_dco = false  
> dynamic\_firewall = false  
> bypass\_sso\_auth = false  
> geo\_sort = false  
> force\_connect = false  
> sso\_auth = true  
> route\_dns = false  
> device\_auth = false  
> host\_id = “id\_server\_name4”  
> host\_address = “ip\_server\_name4”  
> host\_address6 = “ipv6\_server\_name4”  
> host\_networks = [“host\_network”]  
> cur\_timestamp = “2026-04-27 14:24:03.374531”  
> libipt = false  
> [server\_name3][2026-04-27 14:24:03,374][INFO] Starting vpn server  
> server\_id = “”  
> instance\_id = “69ef718395cb03ff428aa592”  
> instances =   
> instances\_count = 0  
> route\_count = 3  
> network = “ipv4/16”  
> network6 = “ipv6/64”  
> ovpn\_dco = false  
> dynamic\_firewall = false  
> bypass\_sso\_auth = false  
> geo\_sort = false  
> force\_connect = false  
> sso\_auth = true  
> route\_dns = false  
> device\_auth = false  
> host\_id = “id\_server\_name3”  
> host\_address = “ip\_server\_name3”  
> host\_address6 = “ipv6\_server\_name3”  
> host\_networks = [“host\_network”]  
> cur\_timestamp = “2026-04-27 14:24:03.374061”  
> libipt = false  
> [server\_name3][2026-04-27 14:24:30,666][INFO] Authenticating user  
> user\_name = “username”  
> factors = [“azure”]  
> [server\_name3][2026-04-27 14:24:30,670][INFO] Client authentication cached, skipping sso token  
> user\_name = “username”  
> org\_name = “org\_name”  
> server\_name = “Pritunl\_server\_name”  
> [server\_name3][2026-04-27 14:24:30,675][INFO] Client authentication cached, skipping password  
> user\_name = “username”  
> org\_name = “org\_name”  
> server\_name = “Pritunl\_server\_name”  
> [server\_name4][2026-04-27 14:24:32,837][INFO] Authenticating user  
> user\_name = “username”  
> factors = [“azure”]  
> [server\_name4][2026-04-27 14:24:32,844][INFO] Client authentication with sso token  
> user\_name = “username”  
> org\_name = “org\_name”  
> server\_name = “Pritunl\_server\_name”  
> [server\_name4][2026-04-27 14:24:32,845][INFO] Client sso authentication, skipping password  
> user\_name = “username”  
> org\_name = “org\_name”  
> server\_name = “Pritunl\_server\_name”

So, based on these tests, my understanding is:

When adding or modifying routes (for example), I should stop the server and start it again, rather than using the Restart Server button.

---

<div class="post-metadata">

### Author: ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)
#### Post date: [April 27, 2026, 8:34pm UTC](https://forum.pritunl.com/t/no-automatic-client-reconnection-with-sso-authentication/3781/4 "2026-04-27T20:34:08Z")

</div>

The server should be stopped before modifying routes then started again. It shouldn’t allow route modifications to occur while the server is running.
