Skip to main content

Check out Interactive Visual Stories to gain hands-on experience with the SSE product features. Click here.

Skyhigh Security

Configure Per-App VPN for Android App in Workspace ONE UEM

Per-App VPN provides granular control over network traffic by routing only selected Android applications through a secure tunnel. This approach protects access to internal resources while allowing personal traffic to bypass the corporate network. To apply these policies, ensure you keep the VPN client connected and running on the device. After updating the app restriction list, restart the VPN service for the changes to take effect.

Create App Configuration Policy  

Follow these steps to configure and deploy a Per-App VPN policy to managed Android devices through Workspace ONE UEM. 

  1. Log in to the Workspace ONE UEM console.
  2. Go to Resources > Native Apps > Public > Add Application.

    1.png
     
  3. Select Android as the Platform from the dropdown.
  4. Select SEARCH APP STORE as Source​​​​.
  5. Enter Skyhigh Client as the app name.
  6. Click Search.

    image (87)_11.png
     
  7. Select the Skyhigh Client app from the search result.

    image (90)_1.png
     
  8. Click SAVE & ASSIGN.

    image (91)_1.png
     
  9. Under the Distribution tab, enter an assignment name in the Name field and add device groups under Assignment Groups as needed.

    image (94)_11.png
     
  10. Go to the Application Configuration tab and enable Send Configuration.

    image (93)_1.png
     
  11. Enter the application package names in the SCAppPerAppInclusion field to specify apps that must use the VPN tunnel, or the SCAppPerAppExclusion field to specify apps that must bypass the VPN tunnel.

NOTE: You can enter either the inclusion list or the exclusion list at a time, not both.


image (95)_1.png

  1. Click SAVE.

    image (95)_2.png
     
  2. Click PUBLISH.

    2026-01-27_12-03-14.png

    The app has been added. 

    2026-01-27_12-04-53.png
     

When the Skyhigh Client app VPN is active and connected, apps in the inclusion list use the VPN tunnel while other apps access the internet directly; when the exclusion list is selected, listed apps access the internet directly, and all other app traffic is routed through the VPN tunnel.

 

 

  • Was this article helpful?