# Scope Android MAM Tunnel blocking to Edge rather than the whole device

> Does Strict Tunnel Mode for an unenrolled Android device block every application's traffic?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-368-scope-android-mam-tunnel-blocking-to-edge-rather-than-the-whole-device/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:25:48+00:00
- Modified: 2026-09-10T02:01:56+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Does Strict Tunnel Mode for an unenrolled Android device block every application's traffic?

## Potentially affected

Use this check for unenrolled Android devices using Microsoft Tunnel for MAM and Edge. Identify the app policy, signed-in work account, and tunnel configuration instead of borrowing assumptions from an enrolled-device VPN profile.

## DSE recommendation

Write the traffic-control requirement in application-specific terms before assigning the setting.

## Article

## Source facts

For Android MAM Tunnel on unenrolled devices, the StrictTunnelMode app setting blocks Edge internet traffic when the MAM connection is unavailable. Microsoft distinguishes it from the enrolled-device VPN-profile setting, which has device-level scope. MAM Tunnel for Android does not support Always-on VPN; enabling it causes connection failure. Microsoft’s documented alternative for this MAM scenario is Strict Tunnel Mode in the Edge app configuration. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/mam-android).

## Applicability

Use this check for unenrolled Android devices using Microsoft Tunnel for MAM and Edge. Identify the app policy, signed-in work account, and tunnel configuration instead of borrowing assumptions from an enrolled-device VPN profile.

## DSE recommendation

Write the traffic-control requirement in application-specific terms before assigning the setting. Ask the service owner whether blocking Edge meets the intended requirement or whether other apps need separately evaluated controls. Keep unsupported Always-on settings out of this MAM design. Explain the expected disconnected behavior to users so they can distinguish an intentional block from a failed internal website.

## Verification

In a representative unenrolled test device, verify work-account Edge browsing with the tunnel connected and deliberately unavailable. Observe other applications separately; do not infer their protection from the Edge result. Restore connectivity and confirm the approved corporate page works again. Record the policy context and actual app behavior, not merely a screenshot of an enabled setting.

## Official references

[Microsoft Learn: Use Microsoft Tunnel VPN with Android devices that don’t enroll with Microsoft Intune](https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/mam-android).

## Primary reference

- Name: Use Microsoft Tunnel VPN with Android devices that don't enroll with Microsoft Intune - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/mam-android
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Scope Android MAM Tunnel blocking to Edge rather than the whole device,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-368-scope-android-mam-tunnel-blocking-to-edge-rather-than-the-whole-device/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
