In modern enterprise environments, remote work has become a permanent part of daily operations. Employees, administrators, and support teams frequently connect to corporate resources from home networks, public Wi-Fi, or other external locations.
While remote connectivity improves productivity and flexibility, it also introduces new security challenges. When remote devices connect to corporate networks, organizations must decide how Internet traffic should be handled.
By default, remote clients may send Internet traffic directly through their local network connection, bypassing corporate security controls. This approach is known as split tunneling, where only traffic destined for internal resources is routed through the corporate network while other traffic uses the local Internet connection.
Although this model improves performance, it can reduce visibility and control over user activity and may expose devices to security risks when connected to untrusted networks.
Microsoft provides a policy that allows administrators to control how Internet traffic is routed when remote devices connect using DirectAccess. Through Microsoft Intune, organizations can configure this policy to determine whether Internet traffic should be routed through the internal corporate network or allowed to access the Internet directly.
When organizations choose to route traffic through the corporate network, Internet activity can be inspected, filtered, and governed by existing security controls such as firewalls, secure web gateways, and monitoring systems.
This configuration strengthens security governance for remote clients and ensures that corporate protection policies continue to apply even when users are working outside the office.
Why This Policy Matters
Remote devices often operate in environments that organizations do not control, including home networks, public hotspots, and shared Internet connections.
Without proper traffic routing controls:
Internet traffic may bypass corporate security inspection
Malicious content may reach endpoints without filtering
User activity may fall outside organizational monitoring
Security policies may not apply when users work remotely
By controlling Internet traffic routing for remote clients:
Organizations maintain visibility over remote user activity
Security inspection and filtering remain active outside the office
Corporate network policies are consistently enforced
The attack surface created by unmanaged networks is reduced
This approach helps ensure that remote work does not weaken the organization’s security posture.
How This Policy Strengthens Security Governance
This policy allows administrators to determine how Internet traffic from remote devices is routed when connected through DirectAccess.
Depending on the configuration:
Internet traffic can be routed through the corporate network, enabling centralized inspection and filtering
Or traffic can be allowed to access the Internet directly from the client device
Routing traffic through the internal network enables organizations to apply their existing security stack including firewall rules, threat inspection, and web filtering to remote devices.
By deploying this configuration through Microsoft Intune, administrators can centrally manage how remote clients interact with the Internet while maintaining consistent security governance across all managed endpoints.
This helps ensure that corporate security policies remain effective even when users operate outside traditional network boundaries.
How to Configure Internet Traffic Routing for Remote Clients Using Intune (Settings Catalog)
You can enforce this policy centrally using the Intune Settings Catalog, ensuring consistent control over how Internet traffic is routed when remote clients connect to the corporate network.
To begin, sign in to the Microsoft Intune admin center and follow the steps below, as illustrated in the screenshot.
Create the Configuration Profile
In the Microsoft Intune admin center:
Navigate to Devices
Select Windows
Click Configuration
Select + Create policy
In the Create a profile pane:
Platform: Windows 10 and later
Profile type: Settings catalog
Click Create to continue.
At this stage, you have created the foundation of a Settings Catalog policy. In the next steps, you will search for and configure the setting that controls how Internet traffic is routed for remote clients when connected through DirectAccess.
This configuration allows organizations to determine whether Internet traffic from remote devices should be routed through the internal corporate network or accessed directly from the client’s local Internet connection, helping maintain visibility, security inspection, and policy enforcement outside the office network.

Define Basic Profile Details
After clicking Create, the next step is to define the basic details of the configuration profile. This stage is important for long-term management, clarity, and governance within Microsoft Intune especially in environments with multiple endpoint hardening policies and security baselines.
Providing a clear Name and a concise but meaningful Description ensures that the purpose of the policy can be quickly understood by administrators and security teams in the future.
As shown in the screenshot, configure the fields as follows.
Policy Name and Description
Name: WIN – Endpoint Hardening – Control Internet Traffic Routing for Remote Clients
Description: This policy strengthens endpoint security by controlling how Internet traffic is routed when remote clients connect to the corporate network, ensuring that corporate security policies and monitoring controls remain enforced outside the office environment.
The Platform field is already pre-selected as Windows, so no changes are required.

Once the name and description are defined, click Next to proceed to the configuration settings.
Configure the Setting Using the Settings Picker
With the profile basics defined, the next step is to configure the policy using the Settings picker, where you select the specific Windows setting that controls how Internet traffic is routed for remote clients.
Click Add settings to open the Settings picker panel.
By default, this setting is not configured, which means Windows will continue using its existing behavior and will not enforce centralized traffic routing for remote clients through Intune.
As shown in the screenshot, use the search field at the top of the Settings picker and type:
Network Connections
Then click Search to filter the results.
From the returned results:
Select the category Administrative Templates → Network → Network Connections
Locate and select the setting Route all traffic through the internal network
Once selected, the setting is added to the configuration profile. Back on the configuration page, change the value to Enabled.
When enabled, remote clients connected through DirectAccess will route all Internet traffic through the internal corporate network instead of accessing the Internet directly through their local connection.
This configuration allows organizations to apply existing security controls such as monitoring, filtering, and network inspection to remote devices, ensuring that corporate security policies remain enforced even when users operate outside the office network.

After configuring the setting, click Next to continue with the profile deployment steps.
Configure Scope Tags (Optional)
Scope tags are used to control who can view and manage this policy within the Microsoft Intune admin center. They are particularly useful in environments with delegated administration, multiple IT teams, or regional management models.
As shown in the screenshot, the Default scope tag is selected. This is the standard and recommended configuration for most environments, as it ensures the policy is visible to all administrators who have access to Intune.
Optionally, custom scope tags can be assigned if you need to:
Restrict policy visibility to specific IT roles or teams
Enforce administrative separation of duties
Support delegated or region-based Intune management
If no additional scope tags are required, keep the Default selection and click Next to continue.

Assignments – Restrict Anonymous Access Policy
After configuring the policy settings, the next step is to assign the policy to the appropriate target group. Assignments define which devices will receive and enforce this configuration, ensuring the policy is applied in a controlled and intentional manner.
In the Assignments tab, click Add groups under Included groups and search for the group you want to target. This approach allows you to deploy the policy gradually, starting with test devices before expanding to production.
As shown in the screenshot, the policy is assigned to the following group:
GRP – MS365Education – Test Computers
Once the group is selected, verify the following:
The group appears under Included groups
The group status is Active
No assignment filters are applied (unless explicitly required)
At this stage, no Excluded groups are configured, which is appropriate for controlled test deployments.

After confirming the assignment, click Next to proceed to the Review + Create step.
Review + Create – Final Validation
The Review + Create step is the final checkpoint before deploying the policy. This is where you verify that all configurations are correct and aligned with your intended remote access security and traffic routing control objective.
Pay special attention to the following items:
Policy name and description:
Confirm that the policy clearly reflects its purpose: controlling how Internet traffic is routed when remote clients connect to the corporate network, ensuring corporate security policies remain enforced outside the office environment.
Configuration settings Verify that Route all traffic through the internal network is set to Enabled under Administrative Templates → Network → Network Connections.
Scope tags: Ensure the correct scope tag is assigned. In this example, the Default scope tag is used.
Assignments: Confirm that the policy is assigned to the intended group, such as GRP – MS365Education – Test Computers, and verify that no unintended exclusions are configured.
This final validation step helps prevent misconfigurations, unintended deployments, or scope issues especially in environments with multiple endpoint policies, delegated administration, and layered security baselines.

Once everything has been validated, click Create to finalize and deploy the policy to the assigned devices.
Monitor Policy Deployment Status
After creating and assigning the WIN – Endpoint Hardening – Control Internet Traffic Routing for Remote Clients configuration profile, the next step is to monitor its deployment status.
This verification ensures that the policy has been successfully applied and is actively controlling how Internet traffic is routed when remote clients connect to the corporate network.
Although Microsoft Intune may take up to 8 hours to automatically deliver configuration profiles, deployment usually occurs much faster. If necessary, you can accelerate the process by:
Triggering a manual device sync from the Company Portal
Forcing a sync directly from the Microsoft Intune admin center
Monitoring deployment status confirms that the traffic routing policy is properly applied to the targeted Windows devices.
How to Verify Policy Deployment Status
To review the deployment results:
In the Microsoft Intune admin center, navigate to Devices → Configuration profiles
Use the search bar to locate the profile: WIN – Endpoint Hardening – Control Internet Traffic Routing for Remote Clients
Select the policy to open the Overview page.
Review Deployment Metrics
Intune provides clear deployment indicators that allow administrators to quickly assess the policy state:
Succeeded – Devices have successfully applied the policy.
In progress – Devices are still processing the configuration or have not checked in yet.
Error – The policy failed to apply and requires investigation.
Not applicable – The device does not support this specific setting.
When devices report Succeeded, it confirms that remote clients will now route Internet traffic through the internal corporate network, allowing organizations to maintain monitoring, filtering, and security inspection for remote devices.
This means:
Internet traffic from remote clients follows corporate routing policies
Security inspection and filtering remain active outside the office network
Remote access security governance is strengthened
Organizational network policies remain enforced for remote devices
Monitoring this stage ensures that your traffic routing configuration is not only deployed but actively protecting remote endpoints across your environment.

Why This Validation Matters
Monitoring the deployment status ensures that the Internet traffic routing policy is correctly applied to remote Windows devices.
This confirmation helps verify that:
Remote clients follow the defined traffic routing behavior
Corporate security inspection and monitoring remain enforced
No deployment failures or unsupported devices exist
Remote access policies are consistently applied across managed endpoints
Validating deployment ensures that your configuration is not only created but actively protecting remote devices in your environment.
Client-Side Verification via Event Viewer
After the device synchronizes with Intune, you can perform a client-side verification to confirm that the policy was successfully applied.
Windows records Intune policy processing events locally, allowing administrators to validate enforcement directly on the device.
How to Verify
Open Event Viewer on the target device
Navigate to:
Applications and Services Logs Microsoft → Windows → DeviceManagement-Enterprise-Diagnostics-Provider → Admin
Select Filter Current Log
Look for Event ID 813 or Event ID 814, which indicate successful processing of Intune configuration policies
Review the event details to confirm that the traffic routing policy was applied successfully.
Pro Tip
Match the event timestamp with the device’s most recent Intune sync to confirm when the policy was evaluated.
Event IDs 813 and 814 are reliable indicators that the configuration policy was processed by the MDM engine.
Why This Matters for Remote Access Security
Remote devices frequently connect from home networks, public Wi-Fi, or unmanaged environments.
By enforcing centralized Internet traffic routing, organizations can:
Maintain visibility over remote network activity
Ensure corporate security inspection remains active
Apply firewall and filtering policies outside the office network
Reduce exposure to untrusted networks
This configuration helps ensure that remote access does not weaken the organization’s security posture.
Key Takeaway
Security does not stop when users leave the office network.
By controlling how Internet traffic is routed for remote clients using Microsoft Intune, organizations can maintain consistent security policies across all managed Windows devices.
A single well-configured policy can ensure that remote connectivity remains secure, monitored, and governed wherever users work
More Information
For additional technical details, official documentation, and deeper insights into this policy and related Microsoft Intune concepts, refer to the Microsoft Learn resources below.
https://learn.microsoft.com/en-us/mem/intune/configuration/settings-catalog
https://learn.microsoft.com/en-us/mem/intune/configuration/device-profiles
https://learn.microsoft.com/en-us/windows-server/remote/remote-access/directaccess/directaccess
https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-admx-networkconnections
https://learn.microsoft.com/en-us/mem/intune/configuration/device-profile-monitor
https://learn.microsoft.com/en-us/mem/intune/configuration/device-profile-troubleshoot
Thank you!
🖥️ Ricardo Barbosa
🎖️ Microsoft MVP | 📘 Microsoft Certified Trainer (MCT)
☁️ Intune & Cloud Architect |💼 Technology Director at Altelix.com
