Hello @hs08 ,
the ASA with multiple contexts = ASA partitioning in logical devices.
VPN profile do you mean RA VPN, Cisco anyconnect ?
if so each context needs to be able to reach an LDAPserver or Radius Server
making switchover for RA VPN between contexts is not recommended.
you need also dynamicDNS and each user has to specify the AD domain
so remote user must log using:
user: <ADdomain-name>\username
password: password
the dyndNS entry will take care of public IPv4 address change
DUO can be used for providing multifactor authentication MFA
Hope to help
Giuseppe