Enable Always On VPN on iOS and macOS devices

Supervised iOS devices can now accept one or more VPN configuration profile(s) that are set as Always On. An Always On VPN configuration provides an automated IKEv2 connection to a VPN without any action being required by end users.

IMPORTANT: Sending an invalid VPN configuration with the Always On check box enabled can prevent a device from having any network communication at all. In the event that an invalid VPN configuration is sent, the only remedy is to remove the MDM profile from the device manually, then re-enroll. Please confirm that the fields in your VPN configuration are accurate before sending.

To manage the Always On VPN feature:

  1. Go to Devices.
  2. Select an existing device(s), or select Enrollment > iOS/macOS.
  3. In the right panel, select VPN.
  4. Click Add+.
    • Complete fields and make selections.
    • Check the Always On check box to enable.
  5. Click Save.