Glossary

Microsoft Tunnel

A VPN gateway for Intune-managed mobile devices providing per-app VPN access to on-prem resources.

Microsoft Tunnel is Microsoft's VPN gateway integrated with Microsoft Intune for managed mobile devices (iOS, Android, Windows). It provides per-app VPN that's controlled through Intune policies and gated by Entra ID Conditional Access — only specific apps route through the tunnel, and access requires the device to meet compliance. Comes in two flavours: Tunnel for MDM (Intune-enrolled corporate devices) and Tunnel for MAM (personal devices with app-protection policies, no enrolment). Modern TLS-based, identity-aware, designed to replace legacy mobile VPNs. Licensed as part of the Intune Suite or standalone.