Skip to main content

August 24, 2026

Configuring Tunnel With Android Standalone

The Omnissa Workspace ONE Tunnel client for Android versions 22.09 and later supports standalone enrollment in addition to the existing MDM workflows. For Standalone enrollment, there is no requirement for device management or Workspace ONE HUB for configuration.

Tunnel Profile for Standalone Enrollment

To setup a new Tunnel profile within the UEM console, go to Security > Tunnel > Gateways. For more information about configuring Tunnel, see Tunnel Configuration Settings.

Follow the setup wizard for the first-time profile creation.

  1. Select Android from the Platform drop-down list and enter a Connection Name for the profile.

  2. Select the appropriate Full Device DTR (Device Traffic Rules) for this profile.

  3. Click Save.

The profile will then be associated to All devices at the Organization Group (OG).

Minimum Requirements for Standalone Enrollment

  • Workspace ONE UEM Console 2410+

  • Android 8+

Current Limitations for Standalone Enrollment

  • Administrators must upload the Tunnel application in the UEM console and assign it to the desired smart groups.

  • Only one Tunnel Profile per platform can be set up at a particular Organization Group (OG).

  • The Tunnel client will only configure if it is enrolled at the OG where the Tunnel Profile is set up.

  • The profile is assigned to All devices at that OG, support for Assignment Groups is planned for a future release.

  • Administrators must allow enrollment for Boxer / Content / Web at the specific OG. This can be done by navigating to Groups and Settings > All Settings > Content > Applications > Workspace ONE Content App. Select Disabled for the Block Enrollment via Content, Boxer, and Web setting.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…