An always-on VPN guarantees that a device's traffic never leaves without going through the VPN: if the VPN disconnects, network access is blocked. It is essential for mobile fleets that reach internal resources. With a MDM like Appaloosa, you push the VPN configuration and enable always-on mode remotely. Here is how.
Always-on: why it matters
Without always-on, a user can turn the VPN off and expose their traffic (or bypass your access rules). Always-on mode enforces the VPN connection permanently and, optionally, blocks the network when the VPN is not connected (lockdown). The result: no company data travels in the clear, even during a drop.
Enable the always-on VPN in Appaloosa
In Configurations → your Android configuration → Security tab, VPN section: set the VPN application to use, then enable "Block network traffic when the VPN is not connected" for always-on mode with lockdown.

You can also set per-application exclusions: some apps (for example an internal tool) go through the VPN, others do not, depending on your needs.
Best practices
- Deploy the VPN app through the MDM first so it is present on every device.
- Enable lockdown (block network outside the VPN) on devices that reach sensitive data.
- Test per-app exclusions so you do not break services that should not go through the VPN.
FAQ
Can the user disable the always-on VPN?
No. In always-on mode enforced by the MDM, the user cannot turn the VPN off; with lockdown, no connection is possible until the VPN is established.
Which VPN apps are supported?
The MDM pushes the configuration to the VPN app of your choice; you simply set which app to use in the configuration.