When configuring Cisco Secure Access for Remote Access VPN (RAVPN) with Endpoint Posture Profiles, administrators can encounter situations where the Operating System posture settings do not display newer Windows 11 versions in the available checkboxes. Specifically, the OS version checks can only show options up to Windows 11 24H2, while newer versions such as Windows 11 25H2 are not explicitly listed as individual checkboxes in the posture profile configuration interface.
This creates uncertainty about how endpoints running unchecked OS versions behave during VPN connection attempts, particularly when Windows 11 25H2 endpoints are observed to successfully establish VPN connections despite not having an explicit checkbox selection in the posture profile configuration.
The configuration area in question is located at: Secure > Endpoint Posture Profiles > VPN Connection > Operating System.
Cisco Secure Access platform configured for Remote Access VPN (RAVPN)
Endpoint Posture Profiles configured with Operating System version checking
Windows 11 endpoints running various versions including 25H2
Posture profile OS settings showing available checkboxes ending at Windows 11 24H2
The behavior observed with Windows 11 25H2 endpoints successfully connecting despite not having an explicit checkbox is due to the Latest selection mechanism in the Endpoint Posture Profiles Operating System settings.
When an endpoint operating system version is not explicitly matched by any of the individual version checkboxes in the posture profile, the expected default behavior would typically result in an authentication error during VPN connection attempts. However, the posture profile system includes a Latest option that encompasses newer OS releases beyond those explicitly listed as individual checkboxes.
To confirm which operating system versions are included under the Latest selection:
Step 1: Navigate to the posture profile configuration. Access Secure > Endpoint Posture Profiles > VPN Connection > Operating System.
Step 2: Check the Latest option information. Look for the information tooltip (i) icon next to the Latest selection to view which specific OS releases are included in this category.
For operating system versions that are not covered by either individual checkboxes or the Latest selection, the system enforces the posture requirement and prevent VPN connectivity. In such cases, endpoints would experience authentication errors during the VPN connection process as the posture check requirement would not be satisfied.
The apparent discrepancy between available individual OS version checkboxes and successful connections from newer OS versions occurs because Cisco Secure Access uses a Latest selection mechanism that automatically includes newer operating system releases. Windows 11 25H2 is included under the Latest category, allowing these endpoints to satisfy the posture requirements even when not explicitly listed as individual checkbox options in the configuration interface. This design allows the posture system to accommodate new OS releases without requiring immediate updates to the individual checkbox listings in the user interface.
| Revision | Publish Date | Comments |
|---|---|---|
1.0 |
13-Aug-2026
|
Initial Release |