Encrypted communications managed from the EMM
The VPN is not an application the user opens when they remember to. It is a policy: it is distributed, activated, monitored and revoked from the EMM console, with certificates from the organisation's PKI and without the device being able to send traffic outside the tunnel.

Always-on and per-app
Always-on VPN
The tunnel is established when the device boots and is maintained without user intervention. With the lockdown option, no application can communicate unless the tunnel is active. This is the default configuration for devices handling sensitive information.
Per-app VPN
Each application (or group) uses its own tunnel to the network segment assigned to it. This allows tactical messaging, email and management applications to reach different resources without exposing them to one another.
Knox VPN framework and protocols
On Galaxy devices, the Knox VPN framework allows the EMM to configure tunnels at system and container level, chain tunnels and apply per-app rules with guarantees that the standard Android API does not provide.
Protocols commonly used in defence and public administration deployments: IPsec/IKEv2 with certificate-based authentication and approved cipher suites, and TLS for application access scenarios. WireGuard is considered only as an option to be evaluated in each project according to its fit with the requirements of the accreditation authority.
The VPN concentrator and client are selected per project: [VPN PRODUCT TO BE DEFINED]. Blindium validates the combination during the pilot.
- IPsec/IKEv2 X.509 certificate authentication, approved cipher suites, periodic re-authentication.
- TLS 1.2/1.3 Application access and App Tunnel; mutual TLS with a device certificate.
- WireGuard Option under evaluation. Lightweight and auditable, pending fit with accreditation requirements.
Dual layer: two independent tunnels
CSfC-style approaches (the NSA's Commercial Solutions for Classified programme) rely on two independent layers of encryption, with components from different vendors, so that the compromise of one layer does not expose the traffic. The device establishes an outer tunnel to the access gateway and an inner tunnel to the destination segment.
Samsung SDS EMM supports dual VPN chaining on Galaxy devices and distributes the configuration and certificates for both layers. The manufacturer states its membership of the CSfC programme; in Spain, this architecture is adapted to the CCN requirements for each classification level.
- Segmentation Internal resources reachable only through the tunnel assigned to each application.
- No exposure No internal service is published on the Internet; the gateway accepts only clients with a valid certificate.
- Revocation A lost device loses access when its certificate is revoked from the EMM.
What is documented in a communications project
- Flow matrix: application, tunnel, destination segment, port and protocol.
- Certificate profile: template, renewal cycle, revocation and root of trust.
- VPN configuration exported from the EMM, versioned as a baseline.
- Test plan: tunnel failure, traffic blocking, network change, revocation.
- Operating procedure for the control centre.
Free MDM/EMM continuity assessment (45 minutes)
A technical session with a specialist to review your situation and return an actionable recommendation. No obligation.
- Current architecture and number of devices
- Data criticality and network or cloud constraints
- Integration with Samsung Knox and mixed fleets
- Transition options and deployment model (on-prem, hybrid or cloud)


