You can force selected applications to connect through your corporate VPN. Your VPN provider must support this feature, and you must publish the apps as managed applications.

Note: Wi-Fi Proxy Auto Configuration is not supported using Per-App VPN.


  1. Navigate to Devices > Profiles & Resources > Profiles > Add > Add Profile > Android.
  2. Select Android to configure the settings.
  3. Select the VPN payload from the list.
  4. Select your VPN vendor from the Connection Type field.
  5. Configure your VPN profile.
  6. Select Per-App VPN Rules to enable the ability to associate the VPN profile to the desired applications. For Workspace ONE Tunnel client, this selection is enabled by default. After the checkbox is enabled, this profile is available for selection under the App Tunneling profiles dropdown in the application assignment page.
  7. Select Save & Publish.
    If Per-App VPN rules are enabled as an update to an existing VPN profile, the devices/applications that were previously using the VPN connection are affected. The VPN connection that was previously routing all apps traffic are disconnected and VPN only applies to applications associated with the updated profile.

What to do next

To configure public apps to use the Per-App VPN profile, see Adding Public Applications for Android in the Application Management for Android publication.