## TL;DR
Create a VPN device configuration profile in Intune (Devices > Configuration > Create > iOS/iPadOS > VPN), pick the connection type your gateway supports (IKEv2, L2TP, or a custom vendor app), fill in the server address, and assign it to the iPhone group. The profile installs silently on supervised devices; on unsupervised devices the user taps through one prompt. Verify in Intune's device install status before closing the ticket.

## Steps
1. In the Intune admin center go to Devices > Configuration > Create > New Policy > iOS/iPadOS > VPN. Expected: the VPN profile editor opens.
2. Choose the connection type: IKEv2 for native iOS VPN, or the custom VPN option with your vendor's app bundle ID (Cisco AnyConnect, GlobalProtect, and similar). Expected: the right fields appear for the type. Native IKEv2 needs no third-party app; vendor apps give more authentication options.
3. Fill in the server address, authentication method (certificate, username and password, or shared secret, per your gateway), and any always-on or on-demand rules. Expected: settings match what your VPN gateway expects. Get these from the network team, not from memory.
4. Assign the profile to the iPhone device group (exclude VIP or exception groups if needed). Expected: the assignment shows the group as included. Do not assign to "All devices" on the first rollout.
5. Pilot on 2 to 3 test iPhones first: check Devices > the device > Device configuration to confirm the profile installed. Expected: status "Succeeded". On the phone, Settings > General > VPN shows the new profile.
6. Roll out to the full group and monitor the profile's install status report. Expected: success rate near 100 percent within a day; chase the failures individually (usually unenrolled devices or outdated iOS).

## Use this when
- New or existing iPhones need corporate VPN configured automatically
- You want zero-touch VPN setup instead of manual phone configuration
- Replacing a manual VPN setup guide with managed profiles

## Not for this skill when
- Android devices (use the Android VPN profile type instead)
- macOS VPN profiles (Intune has separate iOS and macOS profile types)
- Per-app VPN tunneling rules beyond the basic profile (that is a separate app configuration policy)

## Compatibility
- Microsoft Intune; iOS/iPadOS 15 and later; supervised or unsupervised devices

## Variants
### User gets prompted to install the profile
Unsupervised devices require one user tap. Supervised devices (Apple Business Manager enrollment) install silently. If silent install matters, supervise the fleet.
### VPN connects but internal sites do not load
The profile is fine; the issue is DNS or split-tunnel config on the gateway side. Check the on-demand rules and DNS server settings in the profile.

## Why it happens
iOS only accepts VPN configuration through managed profiles or manual entry; there is no scriptable alternative. Intune delivers the profile over the MDM channel, which is why enrollment is a prerequisite and why the profile either installs cleanly or reports a clear error per device.

## Edge cases
- Certificate-based auth needs the CA and client certs deployed as separate Intune profiles first; order matters.
- A stale profile from a previous MDM sticks around after migration; remove old profiles before pushing the new one.
- Major iOS updates can reset VPN on-demand rules; re-push or re-verify after big iOS releases.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_gGlASUz-g6ayPLn0VL_aqw
