Intune's VPN solution: a gateway hosted in containers on Linux. It connects Android Enterprise and iOS/iPadOS devices to resources held on premises, and Microsoft Defender acts as the app on each device.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Microsoft Tunnel in context, with comparison tables and the common traps.
Terms in this definition
- Intune
Microsoft's device management service, once branded Microsoft Endpoint Manager. Its compliance policies are what the compliant-device grant in Conditional Access relies on.
- VPN
Traffic sent through an encrypted tunnel across a public network, as in a site-to-site connection to a VPN gateway in an Azure GatewaySubnet.
- LAMP
Short for Linux, Apache, MySQL and PHP (Perl and Python also fill the P): a widely used open-source stack for web applications whose database is frequently Azure Database for MySQL.
- Android Enterprise
How Google lets organisations manage Android devices that run Google Mobile Services. After a Managed Google Play account is connected, Intune handles four scenarios: fully managed, dedicated, corporate-owned work profile and personally owned work profile.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
Related terms
- Microsoft Tunnel for MAM
Brings Microsoft Tunnel to iOS and Android devices not enrolled in Intune. It needs either the Intune Suite or Intune Plan 2.
- Subject alternative name
The part of a certificate (SAN) that names each host it is good for. Microsoft Tunnel Gateway needs its FQDN or IP address there, and SCEP or PKCS profiles can supply extra values.