Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to deploy a custom VPN configuration that uses per-app VPN and certificate-based authentication. The certificate is already deployed via a PKCS certificate profile. However, the VPN connection fails. What is the most likely reason?
The per-app VPN profile must specify the apps and associate the certificate.
Why this answer
Option B is correct because per-app VPN on iOS requires a VPN profile that includes the app identifier list and associates it with the certificate, and the certificate must be properly configured. Option A is wrong because the certificate is already deployed. Option C is wrong because per-app VPN does not require a separate MDM profile for each app.
Option D is wrong because the VPN server type is not necessarily the issue.