<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect Per-App VPN in Intune for Andoid devices in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-per-app-vpn-in-intune-for-andoid-devices/m-p/434780#M1820</link>
    <description>&lt;P&gt;I need to resolve the following task:&lt;BR /&gt;&lt;BR /&gt;when user start Google Chrome or Edge browser on Android device traffic only from this applications routed via VPN,&lt;BR /&gt;all other just for instance, Microsoft Teams or Outlook should goes directly to Internet.&lt;BR /&gt;Mobile devices are enrolled in Intune with Android Fully Managed Profile&lt;BR /&gt;My approach is:&lt;BR /&gt;I'm try to configure a Per-App VPN with App Configuration Policy for fully managed Android devices policy config&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="GlobalProtectVPN.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36463iFDD122AC5214E6D2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="GlobalProtectVPN.PNG" alt="GlobalProtectVPN.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;BR /&gt;In App List parameter put an application ID of google chrome browser and put in allow list&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;With &lt;STRONG&gt;user-logon Connection method&lt;/STRONG&gt;&amp;nbsp; when user start the phone there is notification that &lt;STRONG&gt;Always-On&lt;/STRONG&gt; is enabled, but in Intune &lt;STRONG&gt;device restriction profile Always-On option is disabled&lt;/STRONG&gt;&lt;BR /&gt;And all traffic from all applications and browser goes via VPN tunnel&lt;BR /&gt;With On-demand Connection Method user need manually start Global Protect VPN client but that's not a good idea because in other case user will have a full access to Internet.&lt;BR /&gt;OS version of Global Protect Gateway is PanOS 9.1.9&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Sep 2021 15:07:11 GMT</pubDate>
    <dc:creator>OSokol</dc:creator>
    <dc:date>2021-09-17T15:07:11Z</dc:date>
    <item>
      <title>Global Protect Per-App VPN in Intune for Andoid devices</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-per-app-vpn-in-intune-for-andoid-devices/m-p/434780#M1820</link>
      <description>&lt;P&gt;I need to resolve the following task:&lt;BR /&gt;&lt;BR /&gt;when user start Google Chrome or Edge browser on Android device traffic only from this applications routed via VPN,&lt;BR /&gt;all other just for instance, Microsoft Teams or Outlook should goes directly to Internet.&lt;BR /&gt;Mobile devices are enrolled in Intune with Android Fully Managed Profile&lt;BR /&gt;My approach is:&lt;BR /&gt;I'm try to configure a Per-App VPN with App Configuration Policy for fully managed Android devices policy config&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="GlobalProtectVPN.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36463iFDD122AC5214E6D2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="GlobalProtectVPN.PNG" alt="GlobalProtectVPN.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;BR /&gt;In App List parameter put an application ID of google chrome browser and put in allow list&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;With &lt;STRONG&gt;user-logon Connection method&lt;/STRONG&gt;&amp;nbsp; when user start the phone there is notification that &lt;STRONG&gt;Always-On&lt;/STRONG&gt; is enabled, but in Intune &lt;STRONG&gt;device restriction profile Always-On option is disabled&lt;/STRONG&gt;&lt;BR /&gt;And all traffic from all applications and browser goes via VPN tunnel&lt;BR /&gt;With On-demand Connection Method user need manually start Global Protect VPN client but that's not a good idea because in other case user will have a full access to Internet.&lt;BR /&gt;OS version of Global Protect Gateway is PanOS 9.1.9&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Sep 2021 15:07:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-per-app-vpn-in-intune-for-andoid-devices/m-p/434780#M1820</guid>
      <dc:creator>OSokol</dc:creator>
      <dc:date>2021-09-17T15:07:11Z</dc:date>
    </item>
  </channel>
</rss>

