Disclosure: This post contains affiliate links; we may earn a commission at no extra cost to you.
There are two completely different ways to run a VPN on Windows 11, and mixing them up is why most setup guides confuse people. Windows 11 ships with a native VPN client built into Settings — it’s a connector, not a VPN service, and it only speaks the corporate-style protocols IT departments use. Then there’s the dedicated app your VPN provider gives you, which is what almost everyone reading this actually wants. This guide covers both, plus which one to pick.
The two paths, and why they’re not interchangeable
Windows 11’s built-in VPN client lives under Settings > Network & internet > VPN > Add VPN, where you choose “Windows (built-in)” from the connection-type dropdown. It supports IKEv2, L2TP/IPsec, SSTP, and legacy PPTP, plus an “Automatic” mode that tries them in order. Critically, it does not speak WireGuard or OpenVPN natively — the two protocols nearly every consumer VPN uses by default in 2026 because they’re faster and better audited. Microsoft doesn’t run public VPN servers either; the built-in client is just a connector waiting for a server address, protocol, and login you supply yourself.
That’s why setting up a commercial VPN this way means manually typing in server hostnames and credentials from your provider’s manual-config pages, and getting only IKEv2 as your fastest option — no kill switch, no split tunneling, no ad/tracker blocking, none of the extras a real app includes.
The dedicated app is the other path, and it’s what this guide recommends for anyone who isn’t specifically configuring a corporate remote-access profile.
Setting up NordVPN’s Windows app (the path most people want)
- Download and install. Go to nordvpn.com, sign in to your account, and download the Windows installer (.exe). Run it and approve the Windows UAC prompt — no manual server entry required.
- Log in. Launch the app and either enter your credentials or use “Log in with browser,” which avoids typing your password into the desktop app directly.
- Pick your protocol. Open Settings (gear icon) > General > VPN Protocol and select NordLynx, NordVPN’s WireGuard-based protocol and the default for a reason — it’s meaningfully faster than the OpenVPN option sitting next to it in the same menu.
- Turn on post-quantum encryption. Under Settings > Connection and security > Post-quantum encryption, toggle it on. NordVPN rolled PQE out to NordLynx in phases starting on Linux in late 2024, reaching Windows through 2025, with full cross-platform availability as of mid-2026 — it’s a real, current feature, not vaporware, and there’s no meaningful reason to leave it off.
- Turn on Threat Protection. This is DNS-level blocking of malicious sites, ads, and trackers, and — this is the part people miss — it keeps working even when you’re not connected to a VPN server. Worth enabling regardless of which server you connect to.
- Connect. Use Quick Connect for the fastest nearby server, or pick a country manually from the map if you need a specific location for streaming or price-shopping.
Windows 11 built-in client: when it actually makes sense
The native client isn’t useless — it’s the right tool if your employer hands you a VPN profile for connecting to a work network, or if you’re connecting to a self-hosted server (a Windows Server VPN role, or a home router set up for remote access) that only speaks IKEv2 or SSTP. For that case: Settings > Network & internet > VPN > Add VPN > “Windows (built-in),” then fill in the server name/address, VPN type (IKEv2 is the strongest built-in option available), and sign-in info from whoever administers that server. It is the wrong tool for a commercial VPN subscription — you’ll be working around the app’s real value, not using it.
Comparison: dedicated app vs. Windows built-in client
| NordVPN Windows App | Windows 11 Built-In Client | |
|---|---|---|
| Protocol | NordLynx (WireGuard-based), OpenVPN option | IKEv2, L2TP/IPsec, SSTP, PPTP (legacy) |
| WireGuard/OpenVPN support | Yes, native | No — unsupported by Windows’ client |
| Setup effort | Install app, log in, connect | Manually enter server address + credentials |
| Kill switch | Yes | No |
| Ad/tracker/malware blocking | Yes (Threat Protection) | No |
| Post-quantum encryption | Yes (toggle in settings) | No |
| Best for | Personal VPN subscriptions, streaming, privacy | Corporate remote access, self-hosted VPN servers |
Honest downsides worth knowing
The dedicated-app route means trusting NordVPN’s client software running with elevated permissions on your machine — a fair tradeoff for most people, but not a “no downside” one if you’re specifically trying to minimize third-party software. The built-in client, meanwhile, technically works for zero extra cost if your provider happens to publish IKEv2 config details, but you lose the kill switch and split-tunneling controls that make a real VPN app worth paying for in the first place — a dropped connection with the native client can silently leak your real IP with no warning.
Common connection problems and how to actually fix them
A NordVPN app that won’t connect on Windows 11 is usually one of three things. First, Windows Defender Firewall or third-party antivirus blocking the app — check the firewall’s allowed-apps list before assuming the VPN itself is broken. Second, a stuck TAP/WireGuard network adapter left over from a previous install; uninstalling and reinstalling the app usually resets it cleanly. Third, ISP-level VPN throttling or blocking on some networks, which NordLynx’s obfuscation can’t always beat — switching to the OpenVPN (TCP) option in the protocol menu sometimes gets through when NordLynx doesn’t. If you’re not sure the VPN is actually active, a quick DNS-leak test (search “DNS leak test” and run one from the browser) confirms whether your real location is showing through — it shouldn’t be, with Threat Protection and NordLynx both on. For the Windows built-in client specifically, connection drops are more often a wrong VPN type selection (SSTP vs. IKEv2 mismatched against what the server actually offers) than anything on your end — confirm the exact protocol with whoever manages that server before troubleshooting further.
Verdict
If you’re setting up a VPN subscription for personal privacy, streaming, or public Wi-Fi protection, install the NordVPN Windows app and switch to NordLynx — skip the built-in client entirely. Only reach for Settings > VPN > Add VPN if IT gave you a work profile or you’re connecting to a server you control that specifically requires IKEv2 or SSTP.
Editor’s pick: NordVPN — NordLynx speed, post-quantum encryption, and Threat Protection make its Windows app the clear choice over Windows’ bare-bones built-in VPN client. (Our NordVPN affiliate program for this article is still being set up — check nordvpn.com directly to sign up.)
FAQ
Does Windows 11 have a VPN built in?
Yes, but it’s a connector for protocols like IKEv2 and SSTP, not a VPN service — Microsoft doesn’t operate servers for it. You still need a VPN provider or your own server to connect to.
Can I use WireGuard with Windows 11’s native VPN settings?
No. Windows’ built-in client doesn’t support WireGuard or OpenVPN — you need your provider’s dedicated app (or a standalone WireGuard/OpenVPN client) for those protocols.
Is NordLynx the same as WireGuard?
NordLynx is NordVPN’s implementation built on the WireGuard protocol, with NordVPN’s own IP-allocation system layered on to address a privacy gap in vanilla WireGuard configs. In the app it behaves like a faster, modern protocol option versus OpenVPN.
Do I need to manually configure anything after installing the NordVPN app?
Not for a normal setup — the app connects with default settings out of the box. The only settings worth deliberately checking are the protocol (NordLynx) and turning on post-quantum encryption and Threat Protection, both of which are off-by-default toggles in some account tiers.
