{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-368-scope-android-mam-tunnel-blocking-to-edge-rather-than-the-whole-device/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-368-scope-android-mam-tunnel-blocking-to-edge-rather-than-the-whole-device/",
        "slug": "dse-20260909-368-scope-android-mam-tunnel-blocking-to-edge-rather-than-the-whole-device",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-368-scope-android-mam-tunnel-blocking-to-edge-rather-than-the-whole-device/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-368-scope-android-mam-tunnel-blocking-to-edge-rather-than-the-whole-device.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-368-scope-android-mam-tunnel-blocking-to-edge-rather-than-the-whole-device/"
        },
        "title": "Scope Android MAM Tunnel blocking to Edge rather than the whole device",
        "summary": "Does Strict Tunnel Mode for an unenrolled Android device block every application's traffic?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:25:48+00:00",
        "modified_at": "2026-09-10T02:01:56+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 235,
        "potentially_affected": "Use this check for unenrolled Android devices using Microsoft Tunnel for MAM and Edge. Identify the app policy, signed-in work account, and tunnel configuration instead of borrowing assumptions from an enrolled-device VPN profile.",
        "dse_recommendation": "Write the traffic-control requirement in application-specific terms before assigning the setting.",
        "primary_source": {
            "name": "Use Microsoft Tunnel VPN with Android devices that don't enroll with Microsoft Intune - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/mam-android",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>For Android MAM Tunnel on unenrolled devices, the StrictTunnelMode app setting blocks Edge internet traffic when the MAM connection is unavailable. Microsoft distinguishes it from the enrolled-device VPN-profile setting, which has device-level scope. MAM Tunnel for Android does not support Always-on VPN; enabling it causes connection failure. Microsoft&#8217;s documented alternative for this MAM scenario is Strict Tunnel Mode in the Edge app configuration. <a href=\"https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/mam-android\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this check for unenrolled Android devices using Microsoft Tunnel for MAM and Edge. Identify the app policy, signed-in work account, and tunnel configuration instead of borrowing assumptions from an enrolled-device VPN profile.</p>\n<h2>DSE recommendation</h2>\n<p>Write the traffic-control requirement in application-specific terms before assigning the setting. Ask the service owner whether blocking Edge meets the intended requirement or whether other apps need separately evaluated controls. Keep unsupported Always-on settings out of this MAM design. Explain the expected disconnected behavior to users so they can distinguish an intentional block from a failed internal website.</p>\n<h2>Verification</h2>\n<p>In a representative unenrolled test device, verify work-account Edge browsing with the tunnel connected and deliberately unavailable. Observe other applications separately; do not infer their protection from the Edge result. Restore connectivity and confirm the approved corporate page works again. Record the policy context and actual app behavior, not merely a screenshot of an enabled setting.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/mam-android\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Use Microsoft Tunnel VPN with Android devices that don&#8217;t enroll with Microsoft Intune</a>.</p>",
        "content_text": "Source facts\nFor Android MAM Tunnel on unenrolled devices, the StrictTunnelMode app setting blocks Edge internet traffic when the MAM connection is unavailable. Microsoft distinguishes it from the enrolled-device VPN-profile setting, which has device-level scope. MAM Tunnel for Android does not support Always-on VPN; enabling it causes connection failure. Microsoft’s documented alternative for this MAM scenario is Strict Tunnel Mode in the Edge app configuration. Microsoft Learn.\nApplicability\nUse this check for unenrolled Android devices using Microsoft Tunnel for MAM and Edge. Identify the app policy, signed-in work account, and tunnel configuration instead of borrowing assumptions from an enrolled-device VPN profile.\nDSE recommendation\nWrite the traffic-control requirement in application-specific terms before assigning the setting. Ask the service owner whether blocking Edge meets the intended requirement or whether other apps need separately evaluated controls. Keep unsupported Always-on settings out of this MAM design. Explain the expected disconnected behavior to users so they can distinguish an intentional block from a failed internal website.\nVerification\nIn a representative unenrolled test device, verify work-account Edge browsing with the tunnel connected and deliberately unavailable. Observe other applications separately; do not infer their protection from the Edge result. Restore connectivity and confirm the approved corporate page works again. Record the policy context and actual app behavior, not merely a screenshot of an enabled setting.\nOfficial references\nMicrosoft Learn: Use Microsoft Tunnel VPN with Android devices that don’t enroll with Microsoft Intune.",
        "content_markdown": "## Source facts\n\nFor Android MAM Tunnel on unenrolled devices, the StrictTunnelMode app setting blocks Edge internet traffic when the MAM connection is unavailable. Microsoft distinguishes it from the enrolled-device VPN-profile setting, which has device-level scope. MAM Tunnel for Android does not support Always-on VPN; enabling it causes connection failure. Microsoft’s documented alternative for this MAM scenario is Strict Tunnel Mode in the Edge app configuration. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/mam-android).\n\n## Applicability\n\nUse this check for unenrolled Android devices using Microsoft Tunnel for MAM and Edge. Identify the app policy, signed-in work account, and tunnel configuration instead of borrowing assumptions from an enrolled-device VPN profile.\n\n## DSE recommendation\n\nWrite the traffic-control requirement in application-specific terms before assigning the setting. Ask the service owner whether blocking Edge meets the intended requirement or whether other apps need separately evaluated controls. Keep unsupported Always-on settings out of this MAM design. Explain the expected disconnected behavior to users so they can distinguish an intentional block from a failed internal website.\n\n## Verification\n\nIn a representative unenrolled test device, verify work-account Edge browsing with the tunnel connected and deliberately unavailable. Observe other applications separately; do not infer their protection from the Edge result. Restore connectivity and confirm the approved corporate page works again. Record the policy context and actual app behavior, not merely a screenshot of an enabled setting.\n\n## Official references\n\n[Microsoft Learn: Use Microsoft Tunnel VPN with Android devices that don’t enroll with Microsoft Intune](https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/mam-android)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-368-scope-android-mam-tunnel-blocking-to-edge-rather-than-the-whole-device/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-368-scope-android-mam-tunnel-blocking-to-edge-rather-than-the-whole-device/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-368-scope-android-mam-tunnel-blocking-to-edge-rather-than-the-whole-device/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Scope Android MAM Tunnel blocking to Edge rather than the whole device",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-368-scope-android-mam-tunnel-blocking-to-edge-rather-than-the-whole-device/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-368-scope-android-mam-tunnel-blocking-to-edge-rather-than-the-whole-device/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-368-scope-android-mam-tunnel-blocking-to-edge-rather-than-the-whole-device/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-368-scope-android-mam-tunnel-blocking-to-edge-rather-than-the-whole-device/",
                "headline": "Scope Android MAM Tunnel blocking to Edge rather than the whole device",
                "description": "Does Strict Tunnel Mode for an unenrolled Android device block every application's traffic?",
                "abstract": "Does Strict Tunnel Mode for an unenrolled Android device block every application's traffic?",
                "articleBody": "Source facts\nFor Android MAM Tunnel on unenrolled devices, the StrictTunnelMode app setting blocks Edge internet traffic when the MAM connection is unavailable. Microsoft distinguishes it from the enrolled-device VPN-profile setting, which has device-level scope. MAM Tunnel for Android does not support Always-on VPN; enabling it causes connection failure. Microsoft’s documented alternative for this MAM scenario is Strict Tunnel Mode in the Edge app configuration. Microsoft Learn.\nApplicability\nUse this check for unenrolled Android devices using Microsoft Tunnel for MAM and Edge. Identify the app policy, signed-in work account, and tunnel configuration instead of borrowing assumptions from an enrolled-device VPN profile.\nDSE recommendation\nWrite the traffic-control requirement in application-specific terms before assigning the setting. Ask the service owner whether blocking Edge meets the intended requirement or whether other apps need separately evaluated controls. Keep unsupported Always-on settings out of this MAM design. Explain the expected disconnected behavior to users so they can distinguish an intentional block from a failed internal website.\nVerification\nIn a representative unenrolled test device, verify work-account Edge browsing with the tunnel connected and deliberately unavailable. Observe other applications separately; do not infer their protection from the Edge result. Restore connectivity and confirm the approved corporate page works again. Record the policy context and actual app behavior, not merely a screenshot of an enabled setting.\nOfficial references\nMicrosoft Learn: Use Microsoft Tunnel VPN with Android devices that don’t enroll with Microsoft Intune.",
                "datePublished": "2026-09-10T00:25:48+00:00",
                "dateModified": "2026-09-10T02:01:56+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-368-scope-android-mam-tunnel-blocking-to-edge-rather-than-the-whole-device/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-368-scope-android-mam-tunnel-blocking-to-edge-rather-than-the-whole-device/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Scope Android MAM Tunnel blocking to Edge rather than the whole device"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 235,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Use Microsoft Tunnel VPN with Android devices that don't enroll with Microsoft Intune - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/mam-android"
                }
            }
        ]
    }
}