Skip to content

Getting VPN working on a corporate iPhone or Android.

Mobile VPN is different: do not full-tunnel a phone or you waste the data plan. Per-app VPN via MDM is the modern path. Microsoft Tunnel, Tailscale and Cloudflare WARP all do this well.

Try this first

  1. 1Configure per-app VPN via Intune or Jamf: only the corp app routes through the tunnel.
  2. 2Avoid always-on unless security requires it, otherwise it eats battery and data.
  3. 3Use cert auth via SCEP instead of password prompts, otherwise users get constant MFA popups on the phone.
  4. 4Test the Wi-Fi to 4G handover so the tunnel reconnects without the user noticing.

When to bring us in

Many BYOD phones without MDM: move to app-level secure tunnel (zero-trust app-by-app) instead of device-level VPN, otherwise you are stuck in privacy debates.

See also

None of the above fits?

Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.

Who are you?

For the AI question we need your email and company, so we can follow up if the AI gets stuck, and to prevent abuse.

Limited to 2 questions per hour and 5 per day, kept lean so the AI stays useful. For more, contacting us directly works better for you and us.

Or skip the DIY entirely

Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.