Configure Microsoft Intune MDM
Create an Always On-VPN Profile
You must first create an Always On-VPN Profile in Intune to configure an Always-On VPN connection for Android devices.
To create an Always On-VPN Profile:
- Log in to the Intune MDM admin portal.
- In the Intune admin portal, go to Devices > Android > Configuration profiles.
- Under Policies, click Create and select New Policy.
- On the Create a profile panel, configure the following:
- Platform. Select Android Enterprise as the platform for the profile.
- Profile type. Select Device restrictions as the profile type.
- Click Create.
Configure VPN Profile Settings
You can now configure the settings of the newly created Always On-VPN profile.
To configure the VPN profile settings:
- In Basics, configure the following setting:
- Name. Enter a descriptive name for the VPN profile.
- Click Next.
- In Configuration settings > Connectivity, configure the following VPN settings:
- For Fully managed, dedicated, and corporate-owned work profile devices:
- Always-on VPN (work profile-level). Select Enable to activate the Always-on VPN connection for your SMCS app.
- VPN client. Select Custom as the VPN client.
- Package ID. Enter com.skyhigh.mcs as the package ID of your SMCS app.
- For Fully managed, dedicated, and corporate-owned work profile devices:
- Click Next.
Assign the VPN Profile
After configuring the settings of the newly created Always On-VPN profile, you can assign the VPN profile to users in your organization.
To assign the VPN profile:
- In Assignments, configure the following setting:
- Add groups. Click Add groups to assign the device restriction profile to Azure AD groups.
- Select groups to include. Select the Azure AD groups from the list. These groups must include the Android devices where you want to enable the Always-On VPN connection.
- Add groups. Click Add groups to assign the device restriction profile to Azure AD groups.
- Click Select.
- In Review + create, review the configured settings of the VPN profile.
NOTE: Make sure that Always-on VPN (work profile-level) is enabled under the Configuration settings.
- Click Create.
Once the VPN profile is created and assigned, the Always-On VPN connection is deployed and enabled on Android devices for users in the assigned groups.