What you need to know
Which identifiers must agree when a custom iOS app integrates Microsoft Tunnel for MAM?
Potentially affected
Apply this review to a line-of-business iOS or iPadOS build using Tunnel for MAM. Separate development, test, and production app identities before evaluating a policy assignment.
DSE recommendation
Maintain a release-specific identifier comparison owned jointly by the app developer and Intune administrator.
Source facts
A custom iOS app using Microsoft Tunnel for MAM must integrate the Intune App SDK, Microsoft Authentication Library, and Tunnel for MAM iOS SDK. Its bundle identifier must agree across the Intune app configuration, Entra app registration, and Xcode project. The application’s client and tenant identifiers must also match the Xcode configuration. The SDK’s VPN operates within the app’s networking layer, so its connection is not displayed in iOS VPN settings. Microsoft Learn.
Applicability
Apply this review to a line-of-business iOS or iPadOS build using Tunnel for MAM. Separate development, test, and production app identities before evaluating a policy assignment.
DSE recommendation
Maintain a release-specific identifier comparison owned jointly by the app developer and Intune administrator. Compare the packaged application’s bundle identifier with the intended registration and policy, then inspect the client and tenant settings in the build configuration. Review the source’s additional permissions, authentication, and app-protection requirements without assuming identifier agreement completes integration. Do not create a second registration merely because a device’s VPN settings show no connection.
Verification
Install an approved test build and authenticate through its actual app flow. Confirm it receives the intended configuration and reaches a harmless internal resource through the expected Tunnel site. Retain the build identity, registration identity, policy assignment, and connection evidence together. Investigate any cross-environment identifier mismatch before broad deployment.
Official references
Review the official source
Use Microsoft Tunnel VPN with iOS/iPad devices that don't enroll with Microsoft Intune - Microsoft Intune | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE