Hi, I just wanted to say that after a long time troubleshooting this with Cisco Support, we did make some progress and found an issue whereby the connection was being attempted by the highest numbered VLAN that I had - in my case it was one that was not configured for the S2S. After disabling VPN participation for that, we found some WMI errors that indicated a potential issue with the account I was using to connect to the domain. TL;DR, I set up RADIUS instead with NPS and used the MFA extension for Azure on top of it and it's working perfectly.
... View more