Defguard releases

Defguard 1.6 brings Zero-touch Enrollment at Enterprise Scale for WireGuard

blog post cover

Zero-touch WireGuard VPN enrollment, Pre-logon VPN for Active Directory, Always-On VPN, native macOS/Windows clients, and enterprise-scale device provisioning. The most complete open-source WireGuard VPN solution.

December 19, 2025

Update
Core

Always-on VPN and Client Traffic Policy

Keep a Service Location connected after login and force all client traffic through the VPN to enforce a strict security policy.

Update
Desktop

Native macOS Client in the App Store

The macOS client moves to a native Swift implementation distributed through the Mac App Store with automatic updates and system VPN integration.

Fix Issue
All Platforms

MTU Settings in All Clients

Manually configure the MTU in client settings to fix dropped packets on restrictive mobile and carrier-grade networks.

Update
Core

Pre-logon VPN for Active Directory

Service Locations establish a WireGuard connection before Windows login, so AD authentication no longer needs to be exposed to the public internet.

Fix Issue
Desktop

Fixed Leftover VPN Connections After Windows Client Upgrade

Installing the 1.6.0 MSI no longer leaves the previous client's VPN connection active after a restart.

Update
Desktop

Windows MSI Installer with Native WireGuard Networking

The Windows client now ships as an MSI package built on WireGuardNT, enabling deployment through Intune and Active Directory GPO.

Update
Core

Zero-touch Enrollment at Enterprise Scale

File-based enrollment configuration plus AD/EntraID integration in the Windows installer enables hands-off provisioning for thousands of devices.