Skip Navigation

Specify which apps use
CylanceGATEWAY
on
iOS
devices in a
Microsoft Intune
environment

You can configure
iOS
devices to recognize
CylanceGATEWAY
as a VPN provider and configure per-app VPN to specify which apps send data through the
CylanceGATEWAY
tunnel. In
Microsoft Intune
, you can configure settings that affect
CylanceGATEWAY
.
To set up per-app tunnel options, you must have permissions for VPN management and app management on
iOS
devices that are activated using
Intune
. To specify which apps use the
CylanceGATEWAY
tunnel in
Intune
, perform the following steps:
  1. In the
    Microsoft Intune
    admin center, add the apps that you want to send through
    CylanceGATEWAY
    to
    Intune
    and assign them to users.
    Only apps that are assigned to users use the
    CylanceGATEWAY
    tunnel. Do not assign the default browser or the
    CylancePROTECT Mobile
    app to users or the device will be unable to establish a tunnel with
    CylanceGATEWAY
    .
  2. Create a VPN profile and include the following settings. For more information on the
    iOS
    and iPadOS settings, see Add VPN settings on iOS and iPadOS devices.
    Setting
    Description
    Connection type
    Custom VPN
    VPN server address
    The value must be 127.0.0.1. This value is not used by
    CylanceGATEWAY
    .
    Authentication Method
    Username & Password
    Split tunneling
    Disable
    VPN identifier
    For
    iOS
    devices, enter com.blackberry.protect
    For macOS devices, enter com.blackberry.big
    • Key:
      key
    • Value:
      value
    Microsoft Intune
    requires one custom attribute.
    CylanceGATEWAY
    does not use this setting. You can enter any attribute.
    Automatic VPN
    Per-app VPN
    Provider Type
    Packet-tunnel
    Safari URLs
    Specify the domains that can establish a connection through the
    CylanceGATEWAY
    tunnel.
    Intune
    does not support wildcards in domains, they are implied. For example, if you enter “org”, implies “*.org”.
    Connections through the
    CylanceGATEWAY
    tunnel can start only if
    CylanceGATEWAY
    is enabled in the
    CylancePROTECT Mobile
    app on the device.
    If you specify blackberry.com as a managed Safari VPN, newly activate
    CylancePROTECT Mobile
    apps will be prevented from activating.
  3. If necessary, have users activate the
    CylancePROTECT Mobile
    app.