Workspace ONE UEM has several options for editing or removing the per-app VPN profile assigned to native applications.

Changes to resources can require a change or the removal of VPN tunnels used to access applications. For example, when users move to different departments in an organization, their access to resources can change. In instances where you need to change or remove the VPN tunnel access for an application, you have several options.

Action Result
Edit the per-app VPN profile associated in the application's flexible deployment assignment. The system associates the changed per-app VPN profile to the application and applicable groups receive the application depending on the assignment settings and priorities.
Change the priority of the flexible deployment assignment. The system pushes the assignment and its configurations, including the per-app VPN profile, depending on the priority. If the assignment is at the top, the devices in the applicable groups receive the profile first.
Deselect the per-app VPN profile in the flexible deployment assignment of the application. The system unassigns the per-app VPN profile from the groups assigned to the application.
Change a device's smart group and the device receives applications entitled to the new group. Flexible deployment assignments are assigned by smart groups. The App Tunneling and Per-App VPN settings are part of the flexible deployment assignment configurations. Move a device to a smart group that you know has the desired application and per-app VPN, and this action changes the profile for the device.

Edit the Per-App VPN Profile of an Internal Application

You can change the app tunnel VPN profile on approved apps to use a different app tunnel to connect to backend and corporate networks.This is a general example of how to edit the per-app VPN profile of an internal application. For public and purchased applications, follow a similar workflow by editing the flexible deployment assignment for that specific application.

  1. Navigate to Resources > Native > Internal in the Workspace ONE UEM console.
  2. Select the radio button for the application and select Assign.
  3. Select the assignment and choose Edit.
  4. In the menu in the setting below App Tunneling, select a different per-app VPN profile.
  5. Select Add and then Save And Publish.

Change the Assignment Priority of the Per-App VPN Profile

You can move the flexible deployment priority up or down to change the app tunnel approved applications use to connect to backend and corporate networks.

  1. Access the flexible deployment assignments of a native application. Follow the substeps to access the assignments for a public application. Internal and purchased applications follow a similar workflow.
    1. To access the assignments of a public application, navigate to Resources > Apps > Native > Public in the Workspace ONE UEM console.
    2. Select the radio button for the application and select Assign.
  2. Select the assignment you want to move and select to Move Up or Move Down. Make any priority changes needed.
  3. Select to Save And Publish.

Remove the Per-App VPN Profile from your Application

Deselect the App Tunnel option in the flexible deployment assignment to disassociate the per-app VPN profile from applications and devices.

  1. Access the flexible deployment assignments of a native application. Follow the substeps to access the assignments for a public application. Internal and purchased applications follow a similar workflow.
    1. To access the assignments of a public application, navigate to Resources > Apps > Native > Public in the Workspace ONE UEM console.
    2. Select the radio button for the application and select Assign.
  2. Select the assignment and choose Edit.
  3. Select Disabled for App Tunneling.
  4. Select Add and then Save And Publish.

Edit a Smart Group

You can edit an established smart group. Any edits that you apply to a smart group affects all policies and profiles to which that smart group is assigned.

  1. Navigate to Groups & Settings > Groups > Assignment Groups.
  2. Select the Edit icon located to the left of the listed smart group that you want to edit. You can also select the smart group name in the Group column. The Edit Smart Group page displays with its existing settings.
  3. In the Edit Smart Group page, alter Criteria or Devices and Users (depending upon which type the smart group was saved with) and then select Next.
  4. In the View Assignments page, you can review which profiles, apps, books, provisions, and policies can be added or removed from the devices as a result.
  5. Select Publish to save your smart group edits. All profiles, apps, books, provisions, and policies tied to this smart group update their device assignments based on this edit.
check-circle-line exclamation-circle-line close-line
Scroll to top icon