Client certificate authentication is available as a two factor authentication method in addition to standard user name and password authentication. If a client certificate is required during authentication, you are automatically prompted to select a client certificate from the Android device client certificate store.
Choose certificate
Select the client certificate from the list of certificates and tap Allow.
By default, the client certificate is set to Choose during login for a VPN connection. If you successfully authenticate with a client certificate, the VPN connection profile is automatically updated to set the client certificate to the one that was chosen.
To reset the client certificate selection, edit the connection and tap the Client Certificate, then set it back to Choose during login.
Edit connection
If no client certificates are installed, an Android No certificates found dialog appears with an option to install a PKCS#12 file located in external storage.