Overview
A VPN that will not connect can fail because of internet connectivity, incorrect credentials, expired authentication, MFA, client state, service outage, certificate problems, or network restrictions.
Why this happens
VPN requires working internet, a reachable VPN gateway, valid identity, allowed device state, and a healthy client configuration.
Before you begin
- Record the exact VPN error.
- Confirm the approved VPN profile.
- Keep the device connected to the internet.
- Do not delete the VPN profile unless IT directs you.
Click-by-click troubleshooting
Step 1: Confirm internet access without VPN
Action: Disconnect VPN if partially connected and test two public websites.
Why this matters: VPN cannot establish reliably without ordinary internet access.
What to look for: Confirm websites load normally.
Expected result: Internet access should work before VPN troubleshooting continues.
Step 2: Review the exact VPN status
Action: Open the approved VPN client or Settings > Network & internet > VPN and select the organization VPN profile.
Why this matters: The displayed state often identifies authentication, gateway, or client failure.
What to look for: Look for credential, certificate, timeout, gateway, or MFA errors.
Expected result: You should capture a specific connection result instead of only "VPN does not work."
Step 3: Verify the user account
Action: Sign in to the organization's primary web portal using the same work identity used for VPN.
Why this matters: This helps determine whether the password or account itself is invalid.
What to look for: Look for account lockout, password expiry, MFA failure, or conditional-access blocks.
Expected result: The work account should authenticate successfully outside the VPN client.
Step 4: Restart the VPN client and device once
Action: Exit the VPN client completely. Restart Windows using Start > Power > Restart, then retry the approved VPN profile.
Why this matters: This clears temporary adapter, client, and authentication-session problems.
What to look for: Compare the error before and after restart.
Expected result: Temporary client-state problems may clear after restart.
Step 5: Test another network if available
Action: If organizational policy allows it, test from a different trusted network such as a mobile hotspot.
Why this matters: Some home or guest networks block VPN protocols or create routing problems.
What to look for: Note whether VPN connects on the alternate network.
Expected result: If VPN works elsewhere, the original network is likely contributing to the failure.
Step 6: Check service status if multiple users are affected
Action: If authorized, review the VPN provider or organization's service status and internal alerts.
Why this matters: A gateway or authentication outage can affect many users simultaneously.
What to look for: Look for active incidents matching the timeframe.
Expected result: You should know whether the problem is device-specific or service-wide.
What to look for
- Web sign-in fails too: identity problem.
- VPN works on alternate network: local network restriction.
- Many users affected: gateway or service outage.
- Certificate or device-compliance error: managed-device issue.
When to stop
When to contact IT
Contact J3 Systems Group if VPN continues to fail after internet and account checks, certificate or compliance errors appear, the profile may be damaged, or multiple users are affected. Include article code KB-15.002 and the exact VPN error.
Need help with this issue?
J3 Systems Group supports small businesses and nonprofits with Microsoft 365, Google Workspace, cybersecurity, devices, documentation, and day-to-day IT operations.
Contact J3 Systems GroupAuthoritative references
Vendor interfaces, licensing, and security guidance can change. Verify current platform behavior against the primary documentation below before making high-impact production changes.