The Per-App VPN Profile setting is enabled for Android apps that are accessed with Workspace ONE Access Mobile SSO for Android.


  • VMware Tunnel configured with the Per-App Tunnel component installed.
  • Android VPN profile created.


  1. In the Workspace ONE UEM console, navigate to Apps & Books > Applications > Native.
  2. Select the tab for the type of application, Internal, Public, or Purchased.
  3. Select Add Application and add an app.
  4. Click Save & Assign.
  5. In the Assignment page, select Add/Edit Assignment and in the Advanced section. In the Advanced section, enable App tunneling and from the Per-App VPN Profile drop-down menu, select the Android VPN profile you created.
  6. Click Save & Publish.
    Enable Per-App VPN for every Android app that is accessed with Mobile SSO for Android. While Per-App VPN is required, tunneling of app data is not required. The Tunnel app is configured on the device as a proxy for device traffic rules. For more information about adding or editing apps, see the VMware Workspace ONE UEM Mobile Application Management Guide on the VMware Workspace ONE UEM documentation page.

What to do next

Create the Network Traffic Rules. See Configure Network Traffic Rules in Workspace ONE UEM.