Last updated: July 24, 2026

How to remotely configure Sophos VPN for iOS/iPadOS devices?

This guide explains how to remotely configure Sophos VPN for iOS/iPadOS devices through MDM. Admins create an iOS/iPadOS profile, select VPN, choose OpenVPN as the connection type, and upload the .ovpn file provided by Sophos along with the account and authentication method (password or certificate). Optional settings include enabling On-Demand VPN for specified domains and configuring proxy settings, before saving and publishing the profile to target devices.

Description

A Virtual Private Network (VPN) ensures only authorized users can access confidential corporate data, from any public network by transmitting all device-web communication on a secure channel. VPN also boosts productivity as it ensures employees can work from anywhere, without worrying about lack of access to specific resource/data. With remote work being adopted extensively, it has become mandatory for IT admins to configure VPN on mobile devices. Configuring VPN can be easily and efficiently done using MDM.

Steps

Follow the steps given below, to configure VPN plug-ins:

  • On the MDM console, click on Device Mgmt tab and select Profiles.
  • Choose iOS/iPadOS and click Continue.
  • Select the VPN tab and fill the requisite parameters as explained below:

Policy Description

PARAMETERDESCRIPTION
Connection type

Select OpenVPN as the connection type.

Connection name

Provide a name for the VPN connection to be configured

AccountSpecify the account that needs access to this VPN. Type %username% to get the appropriate user name, mapped to the device
Custom DataUpload the .opvn file downloaded from your VPN vendor
User authenticationSpecify the authentication type as Password or Certificate or Both
Password (If Password is selected for authentication)Specify the password to be used for user authentication
Identity Certificate (If Certificate is selected for authentication)Specify the identity certificate to be used for certificate-based authentication. You can also use SCEP for this.
Enable On-Demand VPNEnabling On-Demand VPN ensures that a device not present in the corporate network, will be automatically connected to VPN whenever the specified list of server/domains are accessed. If you specify multiple domain names, they should be comma separated.
Proxy Configure the proxy settings to be used for this VPN connection

For more information, refer here

Frequently asked questions

What connection type should I select for Sophos VPN on iOS/iPadOS devices?

Select OpenVPN as the connection type, then provide the account details and upload the .opvn configuration file downloaded from Sophos as the Custom Data.

What authentication options are available for Sophos VPN profiles?

You can specify Password, Certificate, or Both as the user authentication type; certificate-based authentication can use an identity certificate or SCEP.

Can Sophos VPN be configured for both iOS and iPadOS devices?

Yes, this is documented for iOS and iPadOS devices managed through Mobile Device Manager Plus.