Available

Run an Azure VPN gateway on infrastructure you control

You already run the subscription, the directory and the SIEM. The licence and the software gateway both install on infrastructure you control, and your administrators keep signing in with the Microsoft accounts they already have.

Our kernel drivers are attested by Microsoft, and every tunnel is post-quantum by design under FIPS 203 and FIPS 204.

Microsoft Entra ID
+
The Network
Azure And Qs-Wan

Yes, QS-WAN works as an Azure VPN gateway you run yourself

Yes, QS-WAN works as an Azure VPN gateway you run yourself: the licence installs on infrastructure you control, physical or in the cloud, and the software gateway runs on your own infrastructure too. Administrators sign in to the console with Microsoft Entra ID alongside local accounts and on-premises Active Directory, and a device can collect its VPN profile from an embedded Microsoft sign-in window. What exactly sits inside your Azure subscription is agreed with your engineers during deployment, because there’s no published reference architecture for it yet.

What it can do

Three things you already own, and where each one plugs in

One answer for the subscription, one for the directory, and one for the SIEM you already read every morning.

Vpn Power Control
Gateway control from the console, whether that gateway sits in a rack or in rented cloud space

Keep the licence and the gateway on your side of the line

The QS-WAN licence installs on infrastructure you control, and physical or cloud is your call, not a condition of sale. The software gateway runs on your infrastructure too, and it claims its place in the fleet with a single-use code that expires, so a gateway nobody claims never becomes a gateway. If you’d rather not host it at all, the other two delivery routes are a plug-and-play gateway we ship you or hosting on a QuantumNova server, and the product is the same in all three.

Let Entra ID carry on being the staff list

The console sign-in screen offers three providers, labelled Default, [Entra ID](/platform/integrations/entra-id-sso/) and Local AD, so your administrators sign in with the Microsoft work account they already have and you never maintain a second copy of your staff list. On the device, [QNova Client](/platform/qnova-client/) opens an embedded Microsoft sign-in window, and the token that comes back authorises a certificate to be issued for that device. Local credentials keep working when the identity provider is down, and an Entra ID failure reports five phase messages, so you find out which stage broke instead of guessing at eight in the morning.

Login
The sign-in screen, with Default, Entra ID and Local AD side by side
Endpoint Monitoring
Endpoint alerts in the console, and the same events as JSON lines for your SIEM

Send the detections to the SIEM you already read

Every detection and decision is written as one JSON object per line. When the VPN comes up, the client repoints the agent’s telemetry to the tunnelled address, and whatever queued while a device was offline drains on reconnect. Host endpoint monitoring is a QS-WAN capability, built on telemetry from the agent on each machine.

Data and security

What stays on your side, and the one thing we won't draw for you

Both halves of this run on infrastructure you control. The licence installs on your own infrastructure, physical or cloud, and the software gateway runs on your infrastructure too. Identity stays Microsoft’s and your directory stays yours: the device generates its ML-KEM-768 and ML-DSA-65 key pair locally, the private keys are written into the protected profile and never sent anywhere, and only the public keys are registered. We’re a product, not a managed service, so nobody here watches your network. The one thing this page won’t do is draw the inside of your Azure subscription, because the exact deployment shape isn’t published yet and a diagram that turns out to be wrong costs you more than no diagram at all.

Why QS-WAN
Learn more
Ask us

Tell us what's already in the subscription

Which subscription holds your infrastructure, does Entra ID sign your administrators in today, and which SIEM would you want these detections landing in?

Scroll to Top