Configure a VPN safely

Install a trusted VPN profile, enable leak-reducing settings and verify that the connection behaves as expected.

Difficulty
Intermediate
Time
About 25 minutes
Platforms
Windows, macOS, Android, iOS

A virtual private network creates an encrypted connection between your device and a VPN server. It can protect traffic from the local network and replace your visible IP address with the VPN server’s address. It does not make you anonymous, prevent browser tracking or make unsafe sites trustworthy.

Step 1: Decide why you need it

Write down the specific problem:

  • accessing an employer’s internal systems;
  • protecting traffic from an untrusted local network;
  • preventing an internet provider from seeing the destinations you contact;
  • using an IP address in a different location.

If none of these applies, adding a VPN may provide little benefit while creating another company that can observe your connections.

Step 2: Obtain configuration from the real source

For work, use the instructions and software supplied by your organisation.

For a personal service, navigate directly to the provider’s website or verified app-store listing. Avoid search advertisements and third-party download sites. Confirm that the provider documents its ownership, logging policy, supported protocols, security audits and account-recovery process.

Avoid obsolete protocols such as PPTP. Prefer a modern configuration supplied by the service rather than inventing protocol and cryptographic settings yourself.

Step 3: Install the application or profile

The provider may supply an application, a configuration profile or manual server details.

Windows

Open Settings → Network & internet → VPN → Add VPN. Enter only the server, protocol and sign-in information supplied by the provider or administrator. A provider application may configure these settings for you.

macOS

Open System Settings → VPN. Import the supplied configuration or add the service using the server and authentication settings from the provider.

Android

Open Settings → Network and internet → VPN. Choose Add for a manual configuration, or open the trusted provider application.

iPhone and iPad

Use the trusted provider application or an organisation-supplied configuration profile. Review the confirmation screen before allowing a profile to add VPN settings.

Step 4: Enable protective connection settings

Where supported, consider:

  • Always-on or connect automatically on untrusted networks;
  • block connections without VPN, sometimes called a kill switch;
  • DNS protection supplied by the VPN;
  • warnings when the tunnel disconnects.

A kill switch can leave the device offline when the VPN fails. Make sure you know how to disable it before relying on the device during travel or an emergency.

Avoid split tunnelling unless you have a clear reason. It deliberately sends selected applications outside the VPN and can be easy to misconfigure.

Step 5: Verify the result

Before connecting, note your public IP address using a reputable diagnostic site. Connect the VPN and confirm:

  • the VPN application reports a successful connection;
  • the public IP address changed to the expected region;
  • websites still load;
  • DNS and IPv6 tests do not show an unexpected provider;
  • the device warns or blocks traffic when you deliberately disconnect the VPN.

Do not run tests that ask you to install software or browser extensions.

Step 6: Maintain and recover

Keep the VPN application updated. Review connected devices and account activity periodically. Save any recovery information and keep instructions for disabling always-on mode somewhere accessible.

Sources and platform instructions

This page was last reviewed on 26 July 2026