Azure P2S VPN fails with target machine actively refused it

We have Azure P2S VPN setup using OpenVPN and doing a AAD authentication.

It fails with: “Connecting to VPN server failed with exception: No connection could be made because the target machine actively refused it.”

Now VPN client shows success in receiving AAD Credentials token for user and fails after the authentication part.

windows event viewer shows: Error 20227 (RasClient: The error code returned on failure is 2250)

now the interesting thing is its working for few devices and not for rest.

VPN works on personal devices, (devices not part of org)

VPN works on some org devices : lenovo E595

does not work on org devices : lenovo E15

i dont know if its got anything to do with device model or its intune policy or defender for EDR. but we are seeing just randon results depending on which device we test from and NOT user account.

looking for any ideas.

Refused it means in general its hitting a closed port. Could be edr/network security related

Are the devices running the same OS with the same set of patches?

Possible the E15 devices are older and missing some feature or security updates?