# Align the iOS Tunnel app identity across policy, registration, and build

> Which identifiers must agree when a custom iOS app integrates Microsoft Tunnel for MAM?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-394-align-the-ios-tunnel-app-identity-across-policy-registration-and-build/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:25:22+00:00
- Modified: 2026-09-10T02:01:56+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Which identifiers must agree when a custom iOS app integrates Microsoft Tunnel for MAM?

## Potentially affected

Apply this review to a line-of-business iOS or iPadOS build using Tunnel for MAM. Separate development, test, and production app identities before evaluating a policy assignment.

## DSE recommendation

Maintain a release-specific identifier comparison owned jointly by the app developer and Intune administrator.

## Article

## Source facts

A custom iOS app using Microsoft Tunnel for MAM must integrate the Intune App SDK, Microsoft Authentication Library, and Tunnel for MAM iOS SDK. Its bundle identifier must agree across the Intune app configuration, Entra app registration, and Xcode project. The application’s client and tenant identifiers must also match the Xcode configuration. The SDK’s VPN operates within the app’s networking layer, so its connection is not displayed in iOS VPN settings. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/mam-ios).

## Applicability

Apply this review to a line-of-business iOS or iPadOS build using Tunnel for MAM. Separate development, test, and production app identities before evaluating a policy assignment.

## DSE recommendation

Maintain a release-specific identifier comparison owned jointly by the app developer and Intune administrator. Compare the packaged application’s bundle identifier with the intended registration and policy, then inspect the client and tenant settings in the build configuration. Review the source’s additional permissions, authentication, and app-protection requirements without assuming identifier agreement completes integration. Do not create a second registration merely because a device’s VPN settings show no connection.

## Verification

Install an approved test build and authenticate through its actual app flow. Confirm it receives the intended configuration and reaches a harmless internal resource through the expected Tunnel site. Retain the build identity, registration identity, policy assignment, and connection evidence together. Investigate any cross-environment identifier mismatch before broad deployment.

## Official references

[Microsoft Learn: Use Microsoft Tunnel VPN with iOS/iPad devices that don’t enroll with Microsoft Intune](https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/mam-ios).

## Primary reference

- Name: Use Microsoft Tunnel VPN with iOS/iPad devices that don't enroll with Microsoft Intune - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/mam-ios
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Align the iOS Tunnel app identity across policy, registration, and build,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-394-align-the-ios-tunnel-app-identity-across-policy-registration-and-build/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
