Configuring Per App VPN for iOS system apps
These settings apply to supervised devices and devices operating in basic control mode.
The Per App VPN functionality lets a device establish a VPN connection when supported system apps or third-party apps are launched. This functionality is available for IKEv2 and IPSec connections.
The following system apps support Per App VPN connections:
- Mail
- Calendar
- Contacts
- Safari
- Messages
For the Per App VPN functionality to work correctly, the iOS MDM Server version must not be earlier than 15.4.0.2019.
To enable the Per App VPN functionality for supported system apps:
- Perform the initial setup of the VPN connection.
- On the Advanced tab, in the Per App VPN section, select the Enable Per App VPN check box.
- Set up Per App VPN for supported system apps in the corresponding settings of the policy.
Mail
To specify the Per App VPN configuration for the Mail app:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Policies & profiles. In the list of group policies that opens, click the name of the policy that you want to configure.
- In the policy properties window, select Application settings.
- Select iOS and go to the Device configuration section.
- On the Email card, click Settings.
The Email window opens.
- Enable the settings using the Email toggle switch.
- Add a new email account or edit an existing account.
- On the Advanced tab, in the Per App VPN section, select the Enable Per App VPN check box.
- Select a configuration from the Per App VPN configuration drop-down list.
- Click Save.
- Click OK.
- Click Save to save the changes you have made.
Mobile device settings are changed after the next device synchronization with the iOS MDM Server.
As a result, once the policy is applied, Per App VPN is configured for the Mail app.
Calendar
To specify the Per App VPN configuration for the Calendar app:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Policies & profiles. In the list of group policies that opens, click the name of the policy that you want to configure.
- In the policy properties window, select Application settings.
- Select iOS and go to the Device configuration section.
- On the Calendar card, click Settings.
The Calendar window opens.
- Enable the settings using the Calendar toggle switch.
- Add a new calendar account or edit an existing account.
- In the Per App VPN section, select the Enable Per App VPN check box.
- Select a configuration from the Per App VPN configuration drop-down list.
- Click Add.
- Click OK.
- Click Save to save the changes you have made.
Mobile device settings are changed after the next device synchronization with the iOS MDM Server.
As a result, once the policy is applied, Per App VPN is configured for the Calendar app.
Calendar subscriptions
A list of subscriptions to calendars of other CalDAV users, iCal calendars, and other published calendars.
To specify the Per App VPN configuration for calendar subscriptions:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Policies & profiles. In the list of group policies that opens, click the name of the policy that you want to configure.
- In the policy properties window, select Application settings.
- Select iOS and go to the Device configuration section.
- On the Calendar subscriptions card, click Settings.
The Calendar subscriptions window opens.
- Enable the settings using the Calendar subscriptions toggle switch.
- Add a new calendar subscription or edit an existing subscription.
- In the Per App VPN section, select the Enable Per App VPN check box.
- Select a configuration from the Per App VPN configuration drop-down list.
- Click Add.
- Click OK.
- Click Save to save the changes you have made.
Mobile device settings are changed after the next device synchronization with the iOS MDM Server.
As a result, once the policy is applied, Per App VPN is configured for calendar subscriptions.
Contacts
To specify the Per App VPN configuration for the Contacts app:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Policies & profiles. In the list of group policies that opens, click the name of the policy that you want to configure.
- In the policy properties window, select Application settings.
- Select iOS and go to the Device configuration section.
- On the Contacts card, click Settings.
The Contacts window opens.
- Enable the settings using the Contacts toggle switch.
- Add a new contacts account or edit an existing account.
- In the Per App VPN section, select the Enable Per App VPN check box.
- Select a configuration from the Per App VPN configuration drop-down list.
- Click Add.
- Click OK.
- Click Save to save the changes you have made.
Mobile device settings are changed after the next device synchronization with the iOS MDM Server.
As a result, once the policy is applied, Per App VPN is configured for the Contacts app.
Safari
To specify the Per App VPN configuration for Safari:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Policies & profiles. In the list of group policies that opens, click the name of the policy that you want to configure.
- In the policy properties window, select Application settings.
- Select iOS and go to the Device configuration section.
- On the Per App VPN for Safari card, click Settings.
The Per App VPN for Safari window opens.
- Enable the settings using the Per App VPN for Safari toggle switch.
- Click Add.
The Add a website domain window opens.
- Select a configuration from the Per App VPN configuration drop-down list.
- In the Domain name field, specify the website domain that will trigger the VPN connection in Safari. The domain must be in the
www.example.com
format. - Click Add.
The new domain appears in the Safari website domains list.
You can modify or delete Safari website domains in the list using the Edit and Delete buttons at the top of the list.
- Click OK.
- Click Save to save the changes you have made.
Mobile device settings are changed after the next device synchronization with the iOS MDM Server.
As a result, once the policy is applied, Per App VPN is configured for Safari website domains.
LDAP
An LDAP account provides access to corporate data and contacts in the standard iOS apps: Contacts, Messages, and Mail.
To specify the Per App VPN configuration for an LDAP account:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Policies & profiles. In the list of group policies that opens, click the name of the policy that you want to configure.
- In the policy properties window, select Application settings.
- Select iOS and go to the Device configuration section.
- On the LDAP card, click Settings.
The LDAP window opens.
- Enable the settings using the LDAP toggle switch.
- Add a new LDAP account or edit an existing account.
- In the Per App VPN section, select the Enable Per App VPN check box.
- Select a configuration from the Per App VPN configuration drop-down list.
- Click Add.
- Click OK.
- Click Save to save the changes you have made.
Mobile device settings are changed after the next device synchronization with the iOS MDM Server.
As a result, once the policy is applied, Per App VPN is configured for the LDAP account.
Exchange ActiveSync
An Exchange ActiveSync account lets you synchronize corporate email, calendar, contacts, notes, and tasks from the Microsoft Exchange server.
To specify the Per App VPN configuration for an Exchange ActiveSync account:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Policies & profiles. In the list of group policies that opens, click the name of the policy that you want to configure.
- In the policy properties window, select Application settings.
- Select iOS and go to the Device configuration section.
- On the Exchange ActiveSync card, click Settings.
The Exchange ActiveSync window opens.
- Enable the settings using the Exchange ActiveSync toggle switch.
- Add a new Exchange ActiveSync account or edit an existing account.
- On the Additional tab, in the Per App VPN section, select the Enable Per App VPN check box.
- Select a configuration from the Per App VPN configuration drop-down list.
- Click Add.
- Click OK.
- Click Save to save the changes you have made.
Mobile device settings are changed after the next device synchronization with the iOS MDM Server.
As a result, once the policy is applied, Per App VPN is configured for the Exchange ActiveSync account.
Page top