GuideInformationBusiness ContinuityIT

Scope Android MAM Tunnel blocking to Edge rather than the whole device

Does Strict Tunnel Mode for an unenrolled Android device block every application's traffic?

Paired infrastructure paths converging on a stable recovered service.
DSE visual intelligenceContinuity & recoveryGuide · 2 min read
Executive summary

What you need to know

Does Strict Tunnel Mode for an unenrolled Android device block every application's traffic?

Potentially affected

Use this check for unenrolled Android devices using Microsoft Tunnel for MAM and Edge. Identify the app policy, signed-in work account, and tunnel configuration instead of borrowing assumptions from an enrolled-device VPN profile.

DSE recommendation

Write the traffic-control requirement in application-specific terms before assigning the setting.

Source facts

For Android MAM Tunnel on unenrolled devices, the StrictTunnelMode app setting blocks Edge internet traffic when the MAM connection is unavailable. Microsoft distinguishes it from the enrolled-device VPN-profile setting, which has device-level scope. MAM Tunnel for Android does not support Always-on VPN; enabling it causes connection failure. Microsoft’s documented alternative for this MAM scenario is Strict Tunnel Mode in the Edge app configuration. Microsoft Learn.

Applicability

Use this check for unenrolled Android devices using Microsoft Tunnel for MAM and Edge. Identify the app policy, signed-in work account, and tunnel configuration instead of borrowing assumptions from an enrolled-device VPN profile.

DSE recommendation

Write the traffic-control requirement in application-specific terms before assigning the setting. Ask the service owner whether blocking Edge meets the intended requirement or whether other apps need separately evaluated controls. Keep unsupported Always-on settings out of this MAM design. Explain the expected disconnected behavior to users so they can distinguish an intentional block from a failed internal website.

Verification

In a representative unenrolled test device, verify work-account Edge browsing with the tunnel connected and deliberately unavailable. Observe other applications separately; do not infer their protection from the Edge result. Restore connectivity and confirm the approved corporate page works again. Record the policy context and actual app behavior, not merely a screenshot of an enabled setting.

Official references

Microsoft Learn: Use Microsoft Tunnel VPN with Android devices that don’t enroll with Microsoft Intune.

Primary reference

Review the official source

Use Microsoft Tunnel VPN with Android devices that don't enroll with Microsoft Intune - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE