Reviewed and updated in October 2026.
A Virtual Private Network (VPN) is a proven technology for reaching corporate resources from outside the corporate network, across untrusted networks such as the mother of all networks, the internet. Think of a sales consultant who connects from a laptop in a hotel or at a customer's office to check email, download a pitch deck or prepare an order in the internal CRM.
A VPN creates an encrypted tunnel between a device or app and a VPN gateway, so traffic to internal resources cannot be read or altered on the way across untrusted networks. In the enterprise, VPNs come in four main variants: standard, always-on, on-demand and per-app. On managed mobile devices, the UEM usually configures them so users never have to touch a setting.
In 2020 we asked whether VPN was "still a thing" and answered: more than ever. It is still widely used today and remains a solid way to provide managed, controlled connections to back-end infrastructure. But it is no longer the only model, and the picture has become more nuanced:
There are many types of VPN connections. Here are the ones used in the digital workplace, with their benefits and limitations.
The default VPN connection, configured manually or provisioned through EMM/UEM software:
Per-app VPN is the option most EMM/UEM vendors use for mobile app containers.
In all cases, data travels encrypted from the device or app to the VPN gateway. Behind the gateway, inside the corporate network, protection depends on the connection to the destination server, such as a web, database or mail server. If that connection should be encrypted too, it needs its own protection, for example TLS.
Before a VPN tunnel is established, the endpoint must authenticate. Several methods are available and often combined:
For mobile app containers, digital certificates are the usual choice, so users never have to enter credentials. Less interaction means a smoother experience.
It depends on your use case, infrastructure and security requirements. With an EMM/UEM solution, most of this is set up in the background. As an administrator, you specify which apps and which traffic may reach your internal network.
On-demand and per-app VPN remain the best options for most mobile scenarios, because they separate private and work traffic and only connect when needed, which means lower data and battery usage. For new projects, it is worth checking whether ZTNA can replace or complement the VPN for some applications.
A VPN connects a device to a network segment, after which it can usually reach many resources. ZTNA grants access to one application at a time and checks identity and device health for each request, in line with the Zero Trust model in NIST SP 800-207.
Not by itself. A VPN encrypts traffic between the device and the VPN gateway. Traffic between the gateway and the destination server is only encrypted if that connection uses its own protection, such as TLS.
Per-app VPN routes the traffic of selected managed apps through the VPN while personal apps use the regular connection. It is common on BYOD devices and in mobile app containers.
It protects traffic inside the tunnel, but attacks such as TunnelVision (CVE-2024-3661) show that a hostile local network can redirect traffic outside it. Keep VPN clients and operating systems updated and use managed device settings where available.
Demystifying Security, the 2020 series: Mobile Threat Defense (MTD) | Multi-Factor Authentication (MFA) | Identity and Access Management (IAM) | Virtual Private Network (VPN) | Cloud Access Security Broker (CASB) | Zero Trust
Planning VPN profiles for your managed devices or evaluating ZTNA? Our team supports endpoint management and endpoint security projects, and our trainings prepare your administrators. Contact us with any questions.