Last updated: July 24, 2026
This guide explains how to restrict VPN access to specific corporate apps or websites/domains using Mobile Device Manager Plus. Administrators create an iOS VPN profile with VPN On-Demand for specific domains, or a Per-App VPN policy for select apps, then distribute it to devices so only those apps or sites route through the VPN. Certificate-based authentication can also be configured instead of passwords for stronger, more scalable security.
With the increased reliance on mobile devices in organizations, corporate apps have become critical for improving employee productivity. Most organizations prefer restricting access to these apps only within the network, which could in turn hamper employee productivity. Configuring VPN is the simplest solution to allow access to these corporate apps securely even outside the organization. But, configuring VPN could prove to be a difficult task for employees who aren't tech savvy. Mobile Device Manager Plus allows you to configure a VPN policy and distribute it to employee devices. This case can also exist for intranet websites/domains. Using MDM, you can configure VPN for certain apps and/or websites as explained below:
To create an app- or website-specific VPN policy and associate it with devices, follow these steps:
In order to prevent users from specifying passcode for authenticating themselves in case of VPN on-demand, you can use certificates for authentication. Using Certificates has the following advantages:
You can configure certificate as explained here and distribute them on a large scale as explained here.
Create an iOS VPN profile, enable VPN On-Demand under its Configure VPN On-Demand settings, and list the specific domains/websites that should route through the VPN.
Create a Per-App VPN policy and add the specific apps, from the App Repository or managed devices, that should use the VPN - other apps on the device won't route through it.
Certificates are more secure than passwords, easier to manage at scale for large VPN deployments, and aren't bound to an IP address, so remote users with dynamically assigned IPs can still authenticate.