For all supported VPN profiles (i.e. IKEv2, 3 rd party SSL- VPN plugins), Windows Phone 8.1 supports a single sign-on user experience where users will be authenticated to all NTLM- protected domain resources inside an enterprise when VPN is connected for resources that are protected by the VPN profile. The user only needs to enter username/password once
in the authentication dialog (if VPN gateway authentication is U/P based), or in the VPN profile edit page (found in Settings
VPN) if the VPN gateway authentication is certificate based. The intranet sites accessed by the user via IE or other Line of Business applications (with a specified capability) will not ask user for their username/password
after VPN gets connected. Toachieve this function, the MDM server needs to configure the device’s
IE intranet zone settings. Thiswill enable Internet Explorer to treat certain “intranet sites” as trusted, and will provide a single sign-on experience.The MDM server should configure intranet zone settings (URLs, domains, IPs)
to following regkey path via Registry CSP: