Workspace ONE UEM has several options for editing or removing the per-app VPN profile assigned to native applications.
Changes to resources can require a change or the removal of VPN tunnels used to access applications. For example, when users move to different departments in an organization, their access to resources can change. In instances where you need to change or remove the VPN tunnel access for an application, you have several options.
|Edit the per-app VPN profile associated in the application's flexible deployment assignment.||The system associates the changed per-app VPN profile to the application and applicable groups receive the application depending on the assignment settings and priorities.|
|Change the priority of the flexible deployment assignment.||The system pushes the assignment and its configurations, including the per-app VPN profile, depending on the priority. If the assignment is at the top, the devices in the applicable groups receive the profile first.|
|Deselect the per-app VPN profile in the flexible deployment assignment of the application.||The system unassigns the per-app VPN profile from the groups assigned to the application.|
|Change a device's smart group and the device receives applications entitled to the new group.||Flexible deployment assignments are assigned by smart groups. The App Tunneling and Per-App VPN settings are part of the flexible deployment assignment configurations. Move a device to a smart group that you know has the desired application and per-app VPN, and this action changes the profile for the device.|
You can change the app tunnel VPN profile on approved apps to use a different app tunnel to connect to backend and corporate networks.This is a general example of how to edit the per-app VPN profile of an internal application. For public and purchased applications, follow a similar workflow by editing the flexible deployment assignment for that specific application.
You can move the flexible deployment priority up or down to change the app tunnel approved applications use to connect to backend and corporate networks.
Deselect the App Tunnel option in the flexible deployment assignment to disassociate the per-app VPN profile from applications and devices.
You can edit an established smart group. Any edits that you apply to a smart group affects all policies and profiles to which that smart group is assigned.