Configure Per-App VPN for Android App in Microsoft Intune
Per-App VPN provides granular control over network traffic by routing only selected Android applications through a secure tunnel. This approach protects access to internal resources while allowing personal traffic to bypass the corporate network. To apply these policies, ensure you keep the VPN client connected and running on the device. After updating the app restriction list, restart the VPN service for the changes to take effect.
Create App Configuration Policy
Follow these steps to configure and deploy a Per-App VPN policy to managed Android devices through Microsoft Intune.
- Log in to the Microsoft Intune admin center.
- Go to Apps > Android > Configuration.
- Click Create > Managed devices.

- Under the Basics tab, configure the following settings:
- Enter a Name for the profile.
- Select Android Enterprise as the Platform.
- Select All Profile Types as the Profile type.
- Select Skyhigh Client as the Targeted app.
- Click Next.

- Under the Settings tab, from the Configuration settings format dropdown, select Use configuration designer.

- Click Add.

- Select the Configuration key as
SCAppPerAppInclusionto specify apps that must use the VPN tunnel, orSCAppPerAppExclusionto specify apps that must bypass the VPN tunnel. Then click OK.
NOTE: You can select either the inclusion list or the exclusion list at a time, not both.

- Set the Value type to string, and enter the application package names in the Configuration value field to include or exclude them in the Per-App VPN profile.
- Click Next.

- Under the Assignments tab, add the required group in the Included groups setting and click Next.
_1.png?revision=1&size=bestfit&width=754&height=491)
- Under the Review + create tab, review the app configuration policy and click Create.
_1.png?revision=2&size=bestfit&width=784&height=599)
When the Skyhigh Client app VPN is active and connected, apps in the inclusion list use the VPN tunnel while other apps access the internet directly; when the exclusion list is selected, listed apps access the internet directly, and all other app traffic is routed through the VPN tunnel.
