Configure OpenVPN + Mikrotik connection before user login

Dear Mikrotik Admins and Fans,

Our copmputers work in domain (Windows Server 2019 Active Directory) and we have problem, becouse out of office users are get into system with cached credentials. We need an OpenVPN solution, which will connect to our server before user login.

Could we make this with Mikrotik 6.48 or with the 7 version? Now we have the RouterOS 6.48 (configured as OpenVPN server), users can connect OpenVPN via Windows app, but we don’t know how we can configure autoconnect before login. It is needed for GPO working, passwords reset etc. at remote computers. We are using cert authentication and user/passwords from domain via RADIUS servers. But we can change the cofiguration if it is needed for autoconnect.

Maybe somebody had similar problem before?

Thank you for the answer.

Seems to me like it’s more a windows than MT issue.
openvpn client should run using machine account, not user account.
https://superuser.com/questions/1166026/how-to-autostart-and-autoconnect-openvpn-in-windows-10