Configure VPN Policy Profile (Android Enterprise)
The VPN Policy allows administrators to centrally configure secure access to corporate networks using the SureAccess VPN solution. This policy defines connection parameters, network routing rules, web filtering, and application access controls to ensure secure communication between the managed device and the enterprise network.
To remotely configure the VPN Configuration profile on the enrolled device(s), follow these steps:
Navigate to SureMDM Web Console > Profiles > Android > Add > Primary Profile > VPN > Configure.
Enter a Profile Name.
In the VPN Configuration screen, enter the following details and click Save.
General Settings
| Setting | Description |
|---|---|
| Enable SureAccess | Check this option to activate the SureAccess VPN configuration on the device. |
| Connection Name | Enter a unique name for the VPN connection that will be displayed on the device. |
| Always On | Check this option to keep the VPN connection persistent at all times. This ensures that all device traffic routes through the VPN automatically, providing continuous security. |
| Tunnelled CIDR List | Select from the pre-configured CIDR ranges (e.g., 192.168.1.0/24) that are permitted to be accessed via the secure VPN tunnel. |
| Tunnelled FQDN List | Select from the pre-configured Fully Qualified Domain Names (FQDNs) (e.g., erp.company.com) that should be routed through the secure VPN tunnel. |
| Blocked FQDN List | Select from the pre-configured FQDNs to explicitly deny access through the secure tunnel. |
| DNS Resolution Policy | Select the method used to handle DNS queries from the device.
Note: This functionality is supported on SureAccess 3.0.11 or later. |
| Exclusions | Select domains to bypass the tunnel. These domains will be resolved via the user’s local internet. Supported on SureAccess 3.0.11 or later. |
| Enable Web Filtering | Check this option to block user access to websites based on selected content categories. |
| Blocked Category List | Choose the categories of websites (e.g., Social Media, Gaming) that will be blocked when Enable Web Filtering is active. |
| App Access Mode | Select either Allow Specific Apps or Block Specific Apps to control which applications can use the VPN tunnel. |
| Allowed Applications List | (App Access Mode: Allow Specific Apps) Select the applications allowed to operate within the SureAccess VPN. Applications other than the specified ones will be blocked. |
| Blocked Applications List | (App Access Mode: Block Specific Apps) Select the applications blocked from operating within the SureAccess VPN. Applications other than the specified ones will be allowed. |
| Enable Authentication | Check this option to enforce user authentication during the initial SureAccess setup process on the device. Uncheck to bypass authentication. |
Device Trust Evaluation
The Device Trust Evaluation feature allows administrators to verify the security posture of Android Enterprise devices before allowing them to establish a SureAccess VPN connection. SureAccess uses Android Device Trust Signals to evaluate the device against the security rules configured in the profile.
Enable Device Trust Conditional Access
Check Enable Device Trust Conditional Access to perform device trust validation before establishing a SureAccess VPN connection.
When enabled, SureAccess retrieves the available Device Trust Signals from the device and compares them against the configured trust rules. If the option is disabled, Device Trust Evaluation is not performed and SureAccess operates normally. This option is available only when Enable SureAccess is enabled.
| Setting | Description |
|---|---|
| Secure Screen Lock Verification | Validates whether the device has a secure screen lock configured. Select the required Minimum Screen Lock Complexity: Low, Medium, or High. |
| Device Management Mode Enforcement | Validates whether the device is operating under the expected Android Enterprise management mode. Supported modes are Work Profile, Fully Managed Device, and Fully Managed Device With A Work Profile. |
| Device Model and Brand Verification | Validates whether the device matches the configured approved brand and model. Enter one or more values in Allowed Brand(s) and Allowed Device Model(s) as comma-separated values. |
| Android OS Version Range Enforcement | Validates whether the device is running an Android version within the configured Minimum Version and Maximum Version range. |
| Latest Security Patch Level Check | Validates whether the latest security patches are installed for SYSTEM, KERNEL, and SYSTEM_MODULES. |
| Required Network Type | Validates the network transport type used by the device. Supported values include Cellular, Wi-Fi, Cellular / Wi-Fi, Ethernet, Bluetooth, USB, and VPN. |
| Minimum Wi-Fi Security Level | Validates the security level of the connected Wi-Fi network. Supported values are OPEN, PERSONAL, ENTERPRISE_EAP, and ENTERPRISE_192. |
| DNS Over TLS Validation | Validates the DNS over TLS state of the device. Select Active or Inactive as the required DNS state. |
| Google Play Protect | Validates the Google Play Protect state. Supported values are Disabled, Enabled, and Enforced By Policy. |
| Critical App Details Validation | Validates selected critical applications to ensure that they are installed, signed by a trusted source, up to date, and installed from a valid source. |
| WebView Engine Validation | Validates whether the device is using the specified WebView package. Enter the required package name in Required WebView Package. |
| Disk Encryption Validation | Validates the device's disk encryption state. Supported values are Active, Inactive, Active or Active per user, and Active using the default key. |
The configured trust rules are used to determine whether the device meets the required security posture.
Critical App Details Validation
When Enable Critical App Details Validation is enabled, select one or more critical applications to validate. The supported applications are:
- Google Chrome
- Google Play Services
- Android Device Policy
- Google Play Store
- Android System WebView
SureAccess validates whether the selected applications are installed, signed by a trusted certificate authority, up to date, and installed from a valid source such as Google Play Store or MDM.
Block Message
Use the Block Message field to specify the message that should be displayed in the SureAccess application when access is blocked because the device does not meet the configured security requirements.
The default message is: Your device does not meet your organisation's security requirements. Please contact your administrator for assistance.
Disable SureAccess on Non-Compliant Devices
Enable Disable SureAccess on Non-Compliant Devices to enforce the configured Device Trust rules when a device becomes non-compliant.
The newly created profile will be listed in the Profiles section.
Go back to the Home tab and select the device(s).
Click Apply to launch the Apply Job/Profile To Device prompt.
In the Apply Job/Profile To Device prompt, select the created profile and click Apply.