End user devices must be managed by a unified endpoint management (UEM) or mobile device management (MDM) solution, either in "Full Device" (Supervised or Unsupervised) or "User Enrollment" mode.
The UEM or MDM solution must support the configuration and deployment of Per-App VPN profiles and assignment to devices.
User devices must be running the most recent version of the Jamf Trust app.
Important:
Review Using Per-App VPN on Apple Devices before deploying to your devices, to ensure Per-App VPN is the right deployment option for your organization.