Certificates used for Always On VPN are most commonly deployed using on-premises Active Directory and certificate autoenrollment. Of course, this assumes the endpoint is on the internal network and is joined to the domain.
However, some deployment scenarios such as hybrid Azure AD join with Autopilot provisioning and native Azure AD join necessitate the provisioning of certificates without being domain-joined or first having access to the internal network.
Fortunately, Microsoft Endpoint Manager/Intune ...