Demystifying Security: Virtual Private Network (VPN)
Reviewed and updated in October 2026.
A Virtual Private Network (VPN) is a proven technology for reaching corporate resources from outside the corporate network, across untrusted networks such as the mother of all networks, the internet. Think of a sales consultant who connects from a laptop in a hotel or at a customer's office to check email, download a pitch deck or prepare an order in the internal CRM.
A VPN creates an encrypted tunnel between a device or app and a VPN gateway, so traffic to internal resources cannot be read or altered on the way across untrusted networks. In the enterprise, VPNs come in four main variants: standard, always-on, on-demand and per-app. On managed mobile devices, the UEM usually configures them so users never have to touch a setting.
Is VPN still relevant?
In 2020 we asked whether VPN was "still a thing" and answered: more than ever. It is still widely used today and remains a solid way to provide managed, controlled connections to back-end infrastructure. But it is no longer the only model, and the picture has become more nuanced:
- Zero Trust Network Access (ZTNA) grants access to individual applications after checking identity and device health for each request, instead of placing the device on the internal network. NIST describes the underlying model in SP 800-207; see also Demystifying Security: Zero Trust.
- VPN gateways are a prime target. They sit at the network edge and are reachable from the internet. In 2024, CISA issued Emergency Directive 24-01 for vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure. Patching the gateway quickly matters as much as configuring the client.
- The local network can undermine the tunnel. The TunnelVision technique (CVE-2024-3661, May 2024) abuses DHCP option 121 so that an attacker on the same network can route traffic past the VPN tunnel. Read more in TunnelVision Vulnerability and in Everyday Security Risks: Wi-Fi.
Types of VPN
There are many types of VPN connections. Here are the ones used in the digital workplace, with their benefits and limitations.
Standard VPN
The default VPN connection, configured manually or provisioned through EMM/UEM software:
- Turned on and off manually by the user, or automatically by a dedicated VPN client
- All data, from personal and work apps alike, travels to and through the company network
- Potentially insecure traffic from personal apps enters the network
- Reduced connection speeds
Always-on VPN
- Suited to corporate-owned, business-only (COBO) deployments
- For regulated organizations with high security needs (healthcare, government, finance)
- Set up and configured through EMM/UEM software. On iOS and iPadOS it requires supervised devices.
- Connects automatically when the device starts
- All traffic goes through the company network, where it is controlled and monitored
- Can be restricted to managed app traffic only
- Lower administrative effort
- Higher data and battery usage
On-demand VPN
- Connects automatically when specific resources defined by IT are accessed
- Only work traffic travels to and through the company network
- No action required from the user
- Personal app traffic is not affected
- Better connection speed, lower data and battery usage, and less unnecessary traffic in the corporate network
- Requires a dedicated back end and advanced configuration, so it suits larger infrastructures
- Supported natively by most EMM/UEM vendors
Per-app VPN
- Suited to Bring Your Own Device (BYOD) deployments
- IT assigns VPN connections to individual EMM/UEM-managed apps
- Connects automatically when the app reaches a specific resource
- Different apps can use different VPN connections to reach different resources, which keeps their traffic separate
- No action required from the user, and personal app traffic is not affected
- Higher administrative effort, but more efficient data and battery usage
Per-app VPN is the option most EMM/UEM vendors use for mobile app containers.
Security
In all cases, data travels encrypted from the device or app to the VPN gateway. Behind the gateway, inside the corporate network, protection depends on the connection to the destination server, such as a web, database or mail server. If that connection should be encrypted too, it needs its own protection, for example TLS.
Authentication
Before a VPN tunnel is established, the endpoint must authenticate. Several methods are available and often combined:
- User credentials, for example Active Directory username and password
- Biometrics (fingerprint, face recognition)
- Multi-factor authentication, see Demystifying Security: Multi-Factor Authentication
- Digital certificates
For mobile app containers, digital certificates are the usual choice, so users never have to enter credentials. Less interaction means a smoother experience.
Which one should you use?
It depends on your use case, infrastructure and security requirements. With an EMM/UEM solution, most of this is set up in the background. As an administrator, you specify which apps and which traffic may reach your internal network.
On-demand and per-app VPN remain the best options for most mobile scenarios, because they separate private and work traffic and only connect when needed, which means lower data and battery usage. For new projects, it is worth checking whether ZTNA can replace or complement the VPN for some applications.
Frequently asked questions
What is the difference between VPN and ZTNA?
A VPN connects a device to a network segment, after which it can usually reach many resources. ZTNA grants access to one application at a time and checks identity and device health for each request, in line with the Zero Trust model in NIST SP 800-207.
Does a VPN encrypt data end to end?
Not by itself. A VPN encrypts traffic between the device and the VPN gateway. Traffic between the gateway and the destination server is only encrypted if that connection uses its own protection, such as TLS.
What is per-app VPN?
Per-app VPN routes the traffic of selected managed apps through the VPN while personal apps use the regular connection. It is common on BYOD devices and in mobile app containers.
Is a VPN safe on public Wi-Fi?
It protects traffic inside the tunnel, but attacks such as TunnelVision (CVE-2024-3661) show that a hostile local network can redirect traffic outside it. Keep VPN clients and operating systems updated and use managed device settings where available.
Demystifying Security, the 2020 series: Mobile Threat Defense (MTD) | Multi-Factor Authentication (MFA) | Identity and Access Management (IAM) | Virtual Private Network (VPN) | Cloud Access Security Broker (CASB) | Zero Trust
Planning VPN profiles for your managed devices or evaluating ZTNA? Our team supports endpoint management and endpoint security projects, and our trainings prepare your administrators. Contact us with any questions.