{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-394-align-the-ios-tunnel-app-identity-across-policy-registration-and-build/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-394-align-the-ios-tunnel-app-identity-across-policy-registration-and-build/",
        "slug": "dse-20260909-394-align-the-ios-tunnel-app-identity-across-policy-registration-and-build",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-394-align-the-ios-tunnel-app-identity-across-policy-registration-and-build/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-394-align-the-ios-tunnel-app-identity-across-policy-registration-and-build.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-394-align-the-ios-tunnel-app-identity-across-policy-registration-and-build/"
        },
        "title": "Align the iOS Tunnel app identity across policy, registration, and build",
        "summary": "Which identifiers must agree when a custom iOS app integrates Microsoft Tunnel for MAM?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:25:22+00:00",
        "modified_at": "2026-09-10T02:01:56+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 239,
        "potentially_affected": "Apply this review to a line-of-business iOS or iPadOS build using Tunnel for MAM. Separate development, test, and production app identities before evaluating a policy assignment.",
        "dse_recommendation": "Maintain a release-specific identifier comparison owned jointly by the app developer and Intune administrator.",
        "primary_source": {
            "name": "Use Microsoft Tunnel VPN with iOS/iPad devices that don't enroll with Microsoft Intune - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/mam-ios",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>A custom iOS app using Microsoft Tunnel for MAM must integrate the Intune App SDK, Microsoft Authentication Library, and Tunnel for MAM iOS SDK. Its bundle identifier must agree across the Intune app configuration, Entra app registration, and Xcode project. The application&#8217;s client and tenant identifiers must also match the Xcode configuration. The SDK&#8217;s VPN operates within the app&#8217;s networking layer, so its connection is not displayed in iOS VPN settings. <a href=\"https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/mam-ios\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Apply this review to a line-of-business iOS or iPadOS build using Tunnel for MAM. Separate development, test, and production app identities before evaluating a policy assignment.</p>\n<h2>DSE recommendation</h2>\n<p>Maintain a release-specific identifier comparison owned jointly by the app developer and Intune administrator. Compare the packaged application&#8217;s bundle identifier with the intended registration and policy, then inspect the client and tenant settings in the build configuration. Review the source&#8217;s additional permissions, authentication, and app-protection requirements without assuming identifier agreement completes integration. Do not create a second registration merely because a device&#8217;s VPN settings show no connection.</p>\n<h2>Verification</h2>\n<p>Install an approved test build and authenticate through its actual app flow. Confirm it receives the intended configuration and reaches a harmless internal resource through the expected Tunnel site. Retain the build identity, registration identity, policy assignment, and connection evidence together. Investigate any cross-environment identifier mismatch before broad deployment.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/mam-ios\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Use Microsoft Tunnel VPN with iOS/iPad devices that don&#8217;t enroll with Microsoft Intune</a>.</p>",
        "content_text": "Source facts\nA custom iOS app using Microsoft Tunnel for MAM must integrate the Intune App SDK, Microsoft Authentication Library, and Tunnel for MAM iOS SDK. Its bundle identifier must agree across the Intune app configuration, Entra app registration, and Xcode project. The application’s client and tenant identifiers must also match the Xcode configuration. The SDK’s VPN operates within the app’s networking layer, so its connection is not displayed in iOS VPN settings. Microsoft Learn.\nApplicability\nApply this review to a line-of-business iOS or iPadOS build using Tunnel for MAM. Separate development, test, and production app identities before evaluating a policy assignment.\nDSE recommendation\nMaintain a release-specific identifier comparison owned jointly by the app developer and Intune administrator. Compare the packaged application’s bundle identifier with the intended registration and policy, then inspect the client and tenant settings in the build configuration. Review the source’s additional permissions, authentication, and app-protection requirements without assuming identifier agreement completes integration. Do not create a second registration merely because a device’s VPN settings show no connection.\nVerification\nInstall an approved test build and authenticate through its actual app flow. Confirm it receives the intended configuration and reaches a harmless internal resource through the expected Tunnel site. Retain the build identity, registration identity, policy assignment, and connection evidence together. Investigate any cross-environment identifier mismatch before broad deployment.\nOfficial references\nMicrosoft Learn: Use Microsoft Tunnel VPN with iOS/iPad devices that don’t enroll with Microsoft Intune.",
        "content_markdown": "## Source facts\n\nA custom iOS app using Microsoft Tunnel for MAM must integrate the Intune App SDK, Microsoft Authentication Library, and Tunnel for MAM iOS SDK. Its bundle identifier must agree across the Intune app configuration, Entra app registration, and Xcode project. The application’s client and tenant identifiers must also match the Xcode configuration. The SDK’s VPN operates within the app’s networking layer, so its connection is not displayed in iOS VPN settings. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/mam-ios).\n\n## Applicability\n\nApply this review to a line-of-business iOS or iPadOS build using Tunnel for MAM. Separate development, test, and production app identities before evaluating a policy assignment.\n\n## DSE recommendation\n\nMaintain a release-specific identifier comparison owned jointly by the app developer and Intune administrator. Compare the packaged application’s bundle identifier with the intended registration and policy, then inspect the client and tenant settings in the build configuration. Review the source’s additional permissions, authentication, and app-protection requirements without assuming identifier agreement completes integration. Do not create a second registration merely because a device’s VPN settings show no connection.\n\n## Verification\n\nInstall an approved test build and authenticate through its actual app flow. Confirm it receives the intended configuration and reaches a harmless internal resource through the expected Tunnel site. Retain the build identity, registration identity, policy assignment, and connection evidence together. Investigate any cross-environment identifier mismatch before broad deployment.\n\n## Official references\n\n[Microsoft Learn: Use Microsoft Tunnel VPN with iOS/iPad devices that don’t enroll with Microsoft Intune](https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/mam-ios)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-394-align-the-ios-tunnel-app-identity-across-policy-registration-and-build/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-394-align-the-ios-tunnel-app-identity-across-policy-registration-and-build/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-394-align-the-ios-tunnel-app-identity-across-policy-registration-and-build/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Align the iOS Tunnel app identity across policy, registration, and build",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-394-align-the-ios-tunnel-app-identity-across-policy-registration-and-build/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-394-align-the-ios-tunnel-app-identity-across-policy-registration-and-build/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-394-align-the-ios-tunnel-app-identity-across-policy-registration-and-build/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-394-align-the-ios-tunnel-app-identity-across-policy-registration-and-build/",
                "headline": "Align the iOS Tunnel app identity across policy, registration, and build",
                "description": "Which identifiers must agree when a custom iOS app integrates Microsoft Tunnel for MAM?",
                "abstract": "Which identifiers must agree when a custom iOS app integrates Microsoft Tunnel for MAM?",
                "articleBody": "Source facts\nA custom iOS app using Microsoft Tunnel for MAM must integrate the Intune App SDK, Microsoft Authentication Library, and Tunnel for MAM iOS SDK. Its bundle identifier must agree across the Intune app configuration, Entra app registration, and Xcode project. The application’s client and tenant identifiers must also match the Xcode configuration. The SDK’s VPN operates within the app’s networking layer, so its connection is not displayed in iOS VPN settings. Microsoft Learn.\nApplicability\nApply this review to a line-of-business iOS or iPadOS build using Tunnel for MAM. Separate development, test, and production app identities before evaluating a policy assignment.\nDSE recommendation\nMaintain a release-specific identifier comparison owned jointly by the app developer and Intune administrator. Compare the packaged application’s bundle identifier with the intended registration and policy, then inspect the client and tenant settings in the build configuration. Review the source’s additional permissions, authentication, and app-protection requirements without assuming identifier agreement completes integration. Do not create a second registration merely because a device’s VPN settings show no connection.\nVerification\nInstall an approved test build and authenticate through its actual app flow. Confirm it receives the intended configuration and reaches a harmless internal resource through the expected Tunnel site. Retain the build identity, registration identity, policy assignment, and connection evidence together. Investigate any cross-environment identifier mismatch before broad deployment.\nOfficial references\nMicrosoft Learn: Use Microsoft Tunnel VPN with iOS/iPad devices that don’t enroll with Microsoft Intune.",
                "datePublished": "2026-09-10T00:25:22+00:00",
                "dateModified": "2026-09-10T02:01:56+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-394-align-the-ios-tunnel-app-identity-across-policy-registration-and-build/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-394-align-the-ios-tunnel-app-identity-across-policy-registration-and-build/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Align the iOS Tunnel app identity across policy, registration, and build"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 239,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Use Microsoft Tunnel VPN with iOS/iPad devices that don't enroll with Microsoft Intune - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/mam-ios"
                }
            }
        ]
    }
}