Where Does AnyConnect Store VPN Profiles?
Where AnyConnect and Secure Client keep VPN profiles and preferences.
Last updated
AnyConnect keeps machine VPN profiles as XML under ProgramData and per-user preferences under LocalAppData. The profile folder name changed between the AnyConnect and Secure Client eras, so check both spellings on upgraded machines.
Gateways usually push profiles on first connect, making manual copies rare. Local XML matters for preconnect hosts, lab setups and machines that never reach the headend cleanly. macOS and Linux use /opt/cisco paths instead.
Where Cisco AnyConnect stores this, by platform
%ProgramData%\Cisco\Cisco Secure Client\VPN\Profile\
Machine VPN profile XMLs. Older installs use the Cisco AnyConnect Secure Mobility Client variant of this path. Fully quit the GUI (it lingers in the tray) before adding files. User history sits separately in LocalAppData Cisco preferences.
/opt/cisco/secureclient/vpn/profile/
Same predeploy role on Mac under the secureclient tree. Linux uses the identical /opt/cisco/secureclient/vpn/profile path. Profiles download from the headend on connect when present there.
Frequently asked questions
How do I predeploy a VPN profile?
Copy the XML files into the Profile folder on the new machine. The dropdown populates from that directory at GUI launch, so fully quit the client (not just minimize to tray) before checking.
New profiles do not show in the dropdown. Why?
Delete preferences.xml in the user LocalAppData Cisco folder too. The GUI caches host history there separately from ProgramData profiles, and stale entries linger when only one side is replaced.
Notice an outdated path? Let us know.