Skip to main content

Configure VPN Policy Profile (Android Enterprise)

The VPN Policy allows administrators to centrally configure secure access to corporate networks using the SureAccess VPN solution. This policy defines connection parameters, network routing rules, web filtering, and application access controls to ensure secure communication between the managed device and the enterprise network.

To remotely configure the VPN Configuration profile on the enrolled device(s), follow these steps:

  1. Navigate to SureMDM Web Console > Profiles > Android > Add > Primary Profile > VPN > Configure.

  2. Enter a Profile Name.

  3. In the VPN Configuration screen, enter the following details and click Save.

General Settings

SettingDescription
Enable SureAccessCheck this option to activate the SureAccess VPN configuration on the device.
Connection NameEnter a unique name for the VPN connection that will be displayed on the device.
Always OnCheck this option to keep the VPN connection persistent at all times. This ensures that all device traffic routes through the VPN automatically, providing continuous security.
Tunnelled CIDR ListSelect from the pre-configured CIDR ranges (e.g., 192.168.1.0/24) that are permitted to be accessed via the secure VPN tunnel.
Tunnelled FQDN ListSelect from the pre-configured Fully Qualified Domain Names (FQDNs) (e.g., erp.company.com) that should be routed through the secure VPN tunnel.
Blocked FQDN ListSelect from the pre-configured FQDNs to explicitly deny access through the secure tunnel.
DNS Resolution PolicySelect the method used to handle DNS queries from the device.
  • Resolve Only Tunneled FQDN via SureAccess DNS - Only DNS queries that match the configured tunneled FQDN list are resolved through the SureAccess tunnel. All other domains are resolved using the user’s local network.
  • Resolve All Domains via SureAccess DNS - All DNS queries are routed through the SureAccess tunnel, except for domains specified in the exclusion list, which are resolved using the user’s local network.
Note: This functionality is supported on SureAccess 3.0.11 or later.
ExclusionsSelect domains to bypass the tunnel. These domains will be resolved via the user’s local internet.
Supported on SureAccess 3.0.11 or later.
Enable Web FilteringCheck this option to block user access to websites based on selected content categories.
Blocked Category ListChoose the categories of websites (e.g., Social Media, Gaming) that will be blocked when Enable Web Filtering is active.
App Access ModeSelect either Allow Specific Apps or Block Specific Apps to control which applications can use the VPN tunnel.
Allowed Applications List(App Access Mode: Allow Specific Apps) Select the applications allowed to operate within the SureAccess VPN. Applications other than the specified ones will be blocked.
Blocked Applications List(App Access Mode: Block Specific Apps) Select the applications blocked from operating within the SureAccess VPN. Applications other than the specified ones will be allowed.
Enable AuthenticationCheck this option to enforce user authentication during the initial SureAccess setup process on the device. Uncheck to bypass authentication.

Device Trust Evaluation

The Device Trust Evaluation feature allows administrators to verify the security posture of Android Enterprise devices before allowing them to establish a SureAccess VPN connection. SureAccess uses Android Device Trust Signals to evaluate the device against the security rules configured in the profile.

Enable Device Trust Conditional Access

Check Enable Device Trust Conditional Access to perform device trust validation before establishing a SureAccess VPN connection.

When enabled, SureAccess retrieves the available Device Trust Signals from the device and compares them against the configured trust rules. If the option is disabled, Device Trust Evaluation is not performed and SureAccess operates normally. This option is available only when Enable SureAccess is enabled.

SettingDescription
Secure Screen Lock VerificationValidates whether the device has a secure screen lock configured. Select the required Minimum Screen Lock Complexity: Low, Medium, or High.
Device Management Mode EnforcementValidates whether the device is operating under the expected Android Enterprise management mode. Supported modes are Work Profile, Fully Managed Device, and Fully Managed Device With A Work Profile.
Device Model and Brand VerificationValidates whether the device matches the configured approved brand and model. Enter one or more values in Allowed Brand(s) and Allowed Device Model(s) as comma-separated values.
Android OS Version Range EnforcementValidates whether the device is running an Android version within the configured Minimum Version and Maximum Version range.
Latest Security Patch Level CheckValidates whether the latest security patches are installed for SYSTEM, KERNEL, and SYSTEM_MODULES.
Required Network TypeValidates the network transport type used by the device. Supported values include Cellular, Wi-Fi, Cellular / Wi-Fi, Ethernet, Bluetooth, USB, and VPN.
Minimum Wi-Fi Security LevelValidates the security level of the connected Wi-Fi network. Supported values are OPEN, PERSONAL, ENTERPRISE_EAP, and ENTERPRISE_192.
DNS Over TLS ValidationValidates the DNS over TLS state of the device. Select Active or Inactive as the required DNS state.
Google Play ProtectValidates the Google Play Protect state. Supported values are Disabled, Enabled, and Enforced By Policy.
Critical App Details ValidationValidates selected critical applications to ensure that they are installed, signed by a trusted source, up to date, and installed from a valid source.
WebView Engine ValidationValidates whether the device is using the specified WebView package. Enter the required package name in Required WebView Package.
Disk Encryption ValidationValidates the device's disk encryption state. Supported values are Active, Inactive, Active or Active per user, and Active using the default key.

The configured trust rules are used to determine whether the device meets the required security posture.

Critical App Details Validation

When Enable Critical App Details Validation is enabled, select one or more critical applications to validate. The supported applications are:

  • Google Chrome
  • Google Play Services
  • Android Device Policy
  • Google Play Store
  • Android System WebView

SureAccess validates whether the selected applications are installed, signed by a trusted certificate authority, up to date, and installed from a valid source such as Google Play Store or MDM.

Block Message

Use the Block Message field to specify the message that should be displayed in the SureAccess application when access is blocked because the device does not meet the configured security requirements.

The default message is: Your device does not meet your organisation's security requirements. Please contact your administrator for assistance.

Disable SureAccess on Non-Compliant Devices

Enable Disable SureAccess on Non-Compliant Devices to enforce the configured Device Trust rules when a device becomes non-compliant.

The newly created profile will be listed in the Profiles section.

  1. Go back to the Home tab and select the device(s).

  2. Click Apply to launch the Apply Job/Profile To Device prompt.

  3. In the Apply Job/Profile To Device prompt, select the created profile and click Apply.

💬 Help us improve this documentation

Was this information useful?

Your feedback helps us keep our documentation accurate, up to date, and useful.