Recently we have implemented Meraki VPN client and have noticed a massive change of failed logins in the event log on the domain controller (ID: 4625) that display the users meraki email/username (which is different from the users samaccount) as the failed login account. Any ideas why the VPN credentials are being sent to the DC? VPN Client authentication is using Meraki Cloud.
... View more