AllowVPNOverCellular
Control whether VPN connections can use cellular networks.
OMA-URI
./Device/Vendor/MSFT/Policy/Config/Connectivity/AllowVPNOverCellular
./Device/Vendor/MSFT/Policy/Config/Connectivity/AllowVPNOverCellular
Deployment playbook
Assign it, sync it, prove it
A correct OMA-URI can still fail because of scope, format, applicability, targeting, conflict, or device state.
Likely causes
- The path, device scope, integer format, or configured value does not match this CSP record.
- The setting is not applicable to the device edition, Windows build, management mode, or hardware.
- Assignment filters, exclusions, stale check-in, or another policy source changed the effective configuration.
Recommended fix
- Distinguish ordinary cellular use from roaming behavior.
- Check the VPN profile and cellular interface state.
- Review related Connectivity CSP policies.
Verify
- Trigger a device sync, then wait for a new check-in rather than reading the previous report state.
- Review the per-setting status and compare the profile, assignment, filter evaluation, and conflict details.
- On Windows, correlate the fresh sync with DMEDP/Admin events and the MDM diagnostic report.
- Verify the operating-system effect directly; a successful policy report is not always proof of the desired outcome.
Escalate when
- The current Microsoft CSP documentation lists the path/value as applicable but a freshly synced supported device still rejects it.
- Multiple devices fail with the same event or SyncML status after targeting and conflicts are eliminated.
- You can provide the policy JSON, assignments/filters, device build/edition, UTC sync time, per-setting status, and redacted diagnostics.
Copy this OMA-URI
./Device/Vendor/MSFT/Policy/Config/Connectivity/AllowVPNOverCellularUse scope Device, format Integer, and a value allowed by the current Microsoft documentation.
Read recent Windows MDM events
Get-WinEvent -LogName 'Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin' -MaxEvents 50 | Select-Object TimeCreated,Id,LevelDisplayName,MessageRead-only. Run on the affected Windows device and correlate the output with the latest sync time.
Collect an MDM diagnostic archive
mdmdiagnosticstool.exe -area "DeviceEnrollment;DeviceProvisioning;Autopilot" -zip "C:\Users\Public\Documents\MDMDiagReport.zip"Creates a local archive. Redact tenant, user, device, certificate, and network identifiers before sharing.
Deployment values
- Scope
- Device
- Format
- Integer
- Values
- 0 blocks VPN over cellular; 1 allows it.
Operational checks
- Distinguish ordinary cellular use from roaming behavior.
- Check the VPN profile and cellular interface state.
- Review related Connectivity CSP policies.
Advertisement
