In a remote access (On-Demand) VPN configuration,
users must manually launch the app to establish the secure GlobalProtect
connection. Traffic that matches specific filters (such as port
and IP address) configured on the GlobalProtect gateway is routed
through the VPN tunnel only after users initiate and establish the
connection.
Because Workspace ONE does not yet list GlobalProtect as an official connection provider for
Windows endpoints, you must select an alternate VPN provider, edit the settings
for the GlobalProtect app, and import the configuration back into the VPN
profile as described in the following workflow.
Use the following steps to configure a user-initiated remote access VPN configuration for Windows
10 UWP endpoints using Workspace ONE: