Browse docs

Always-On VPN

This policy lets you define which VPN app stays permanently active on the device.

The Always-On VPN policy determines which already installed VPN app should stay permanently active on an Android Enterprise device. Unlike the StrongSwan configurations →, which equip a specific VPN app with its own profile, this policy only selects which app acts as the always-on VPN – the app itself must be installed separately via Manage Apps →, since it is not deployed automatically by this policy.

Settings

  • Select the Always-On VPN app – the app that should remain permanently active as the VPN connection.
  • Deny network connection if VPN is not connected (lockdown mode) – blocks all network access as long as the VPN connection is not established.

Support

  • Managed devices (Device Owner)
  • COPE work profile (Personal Profile Enabled)
  • Work profile (Profile Owner/BYOD)
Top