Cyber Cloud Ops Logo
Microsoft Intune

Securing Remote Clients: Controlling Internet Traffic Routing with Microsoft Intune

By Admin User
March 12, 2026
12 min
Securing Remote Clients: Controlling Internet Traffic Routing with Microsoft Intune

In modern enterprise environments, remote work has become a permanent part of daily operations. Employees, administrators, and support teams frequently connect to corporate resources from home networks, public Wi-Fi, or other external locations.

While remote connectivity improves productivity and flexibility, it also introduces new security challenges. When remote devices connect to corporate networks, organizations must decide how Internet traffic should be handled.

By default, remote clients may send Internet traffic directly through their local network connection, bypassing corporate security controls. This approach is known as split tunneling, where only traffic destined for internal resources is routed through the corporate network while other traffic uses the local Internet connection.

Although this model improves performance, it can reduce visibility and control over user activity and may expose devices to security risks when connected to untrusted networks.

Microsoft provides a policy that allows administrators to control how Internet traffic is routed when remote devices connect using DirectAccess. Through Microsoft Intune, organizations can configure this policy to determine whether Internet traffic should be routed through the internal corporate network or allowed to access the Internet directly.

When organizations choose to route traffic through the corporate network, Internet activity can be inspected, filtered, and governed by existing security controls such as firewalls, secure web gateways, and monitoring systems.

This configuration strengthens security governance for remote clients and ensures that corporate protection policies continue to apply even when users are working outside the office.

Why This Policy Matters

Remote devices often operate in environments that organizations do not control, including home networks, public hotspots, and shared Internet connections.

Without proper traffic routing controls:

  • Internet traffic may bypass corporate security inspection

  • Malicious content may reach endpoints without filtering

  • User activity may fall outside organizational monitoring

  • Security policies may not apply when users work remotely

By controlling Internet traffic routing for remote clients:

  • Organizations maintain visibility over remote user activity

  • Security inspection and filtering remain active outside the office

  • Corporate network policies are consistently enforced

  • The attack surface created by unmanaged networks is reduced

This approach helps ensure that remote work does not weaken the organization’s security posture.

How This Policy Strengthens Security Governance

This policy allows administrators to determine how Internet traffic from remote devices is routed when connected through DirectAccess.

Depending on the configuration:

  • Internet traffic can be routed through the corporate network, enabling centralized inspection and filtering

  • Or traffic can be allowed to access the Internet directly from the client device

Routing traffic through the internal network enables organizations to apply their existing security stack including firewall rules, threat inspection, and web filtering to remote devices.

By deploying this configuration through Microsoft Intune, administrators can centrally manage how remote clients interact with the Internet while maintaining consistent security governance across all managed endpoints.

This helps ensure that corporate security policies remain effective even when users operate outside traditional network boundaries.

How to Configure Internet Traffic Routing for Remote Clients Using Intune (Settings Catalog)

You can enforce this policy centrally using the Intune Settings Catalog, ensuring consistent control over how Internet traffic is routed when remote clients connect to the corporate network.

To begin, sign in to the Microsoft Intune admin center and follow the steps below, as illustrated in the screenshot.

Create the Configuration Profile

In the Microsoft Intune admin center:

  • Navigate to Devices

  • Select Windows

  • Click Configuration

  • Select + Create policy

In the Create a profile pane:

  • Platform: Windows 10 and later

  • Profile type: Settings catalog

Click Create to continue.

At this stage, you have created the foundation of a Settings Catalog policy. In the next steps, you will search for and configure the setting that controls how Internet traffic is routed for remote clients when connected through DirectAccess.

This configuration allows organizations to determine whether Internet traffic from remote devices should be routed through the internal corporate network or accessed directly from the client’s local Internet connection, helping maintain visibility, security inspection, and policy enforcement outside the office network.

Controlling Internet Traffic Routing for Remote Clients with Microsoft Intune - Fig. 01

Define Basic Profile Details

After clicking Create, the next step is to define the basic details of the configuration profile. This stage is important for long-term management, clarity, and governance within Microsoft Intune especially in environments with multiple endpoint hardening policies and security baselines.

Providing a clear Name and a concise but meaningful Description ensures that the purpose of the policy can be quickly understood by administrators and security teams in the future.

As shown in the screenshot, configure the fields as follows.

Policy Name and Description

Name: WIN – Endpoint Hardening – Control Internet Traffic Routing for Remote Clients

Description: This policy strengthens endpoint security by controlling how Internet traffic is routed when remote clients connect to the corporate network, ensuring that corporate security policies and monitoring controls remain enforced outside the office environment.

The Platform field is already pre-selected as Windows, so no changes are required.

Controlling Internet Traffic Routing for Remote Clients with Microsoft Intune - Fig. 02

Once the name and description are defined, click Next to proceed to the configuration settings.

Configure the Setting Using the Settings Picker

With the profile basics defined, the next step is to configure the policy using the Settings picker, where you select the specific Windows setting that controls how Internet traffic is routed for remote clients.

Click Add settings to open the Settings picker panel.

By default, this setting is not configured, which means Windows will continue using its existing behavior and will not enforce centralized traffic routing for remote clients through Intune.

As shown in the screenshot, use the search field at the top of the Settings picker and type:

Network Connections

Then click Search to filter the results.

From the returned results:

  • Select the category Administrative Templates → Network → Network Connections

  • Locate and select the setting Route all traffic through the internal network

Once selected, the setting is added to the configuration profile. Back on the configuration page, change the value to Enabled.

When enabled, remote clients connected through DirectAccess will route all Internet traffic through the internal corporate network instead of accessing the Internet directly through their local connection.

This configuration allows organizations to apply existing security controls such as monitoring, filtering, and network inspection to remote devices, ensuring that corporate security policies remain enforced even when users operate outside the office network.

Controlling Internet Traffic Routing for Remote Clients wit Microsoft Intune - Fig. 03

After configuring the setting, click Next to continue with the profile deployment steps.

Configure Scope Tags (Optional)

Scope tags are used to control who can view and manage this policy within the Microsoft Intune admin center. They are particularly useful in environments with delegated administration, multiple IT teams, or regional management models.

As shown in the screenshot, the Default scope tag is selected. This is the standard and recommended configuration for most environments, as it ensures the policy is visible to all administrators who have access to Intune.

Optionally, custom scope tags can be assigned if you need to:

  • Restrict policy visibility to specific IT roles or teams

  • Enforce administrative separation of duties

  • Support delegated or region-based Intune management

If no additional scope tags are required, keep the Default selection and click Next to continue.

Controlling Internet Traffic Routing for Remote Clients with Microsoft Intune - Fig. 04

Assignments – Restrict Anonymous Access Policy

After configuring the policy settings, the next step is to assign the policy to the appropriate target group. Assignments define which devices will receive and enforce this configuration, ensuring the policy is applied in a controlled and intentional manner.

In the Assignments tab, click Add groups under Included groups and search for the group you want to target. This approach allows you to deploy the policy gradually, starting with test devices before expanding to production.

As shown in the screenshot, the policy is assigned to the following group:

GRP – MS365Education – Test Computers

Once the group is selected, verify the following:

  • The group appears under Included groups

  • The group status is Active

  • No assignment filters are applied (unless explicitly required)

At this stage, no Excluded groups are configured, which is appropriate for controlled test deployments.

Controlling Internet Traffic Routing for Remote Clients with Microsoft Intune - Fig. 05

After confirming the assignment, click Next to proceed to the Review + Create step.

Review + Create – Final Validation

The Review + Create step is the final checkpoint before deploying the policy. This is where you verify that all configurations are correct and aligned with your intended remote access security and traffic routing control objective.

Pay special attention to the following items:

Policy name and description:

  • Confirm that the policy clearly reflects its purpose: controlling how Internet traffic is routed when remote clients connect to the corporate network, ensuring corporate security policies remain enforced outside the office environment.

Configuration settings Verify that Route all traffic through the internal network is set to Enabled under Administrative Templates → Network → Network Connections.

Scope tags: Ensure the correct scope tag is assigned. In this example, the Default scope tag is used.

Assignments: Confirm that the policy is assigned to the intended group, such as GRP – MS365Education – Test Computers, and verify that no unintended exclusions are configured.

This final validation step helps prevent misconfigurations, unintended deployments, or scope issues especially in environments with multiple endpoint policies, delegated administration, and layered security baselines.

Controlling Internet Traffic Routing for Remote Clients with Microsoft Intune - Fig. 06

Once everything has been validated, click Create to finalize and deploy the policy to the assigned devices.

Monitor Policy Deployment Status

After creating and assigning the WIN – Endpoint Hardening – Control Internet Traffic Routing for Remote Clients configuration profile, the next step is to monitor its deployment status.

This verification ensures that the policy has been successfully applied and is actively controlling how Internet traffic is routed when remote clients connect to the corporate network.

Although Microsoft Intune may take up to 8 hours to automatically deliver configuration profiles, deployment usually occurs much faster. If necessary, you can accelerate the process by:

  • Triggering a manual device sync from the Company Portal

  • Forcing a sync directly from the Microsoft Intune admin center

Monitoring deployment status confirms that the traffic routing policy is properly applied to the targeted Windows devices.

How to Verify Policy Deployment Status

To review the deployment results:

  • In the Microsoft Intune admin center, navigate to Devices → Configuration profiles

  • Use the search bar to locate the profile: WIN – Endpoint Hardening – Control Internet Traffic Routing for Remote Clients

  • Select the policy to open the Overview page.

Review Deployment Metrics

Intune provides clear deployment indicators that allow administrators to quickly assess the policy state:

  • Succeeded – Devices have successfully applied the policy.

  • In progress – Devices are still processing the configuration or have not checked in yet.

  • Error – The policy failed to apply and requires investigation.

  • Not applicable – The device does not support this specific setting.

When devices report Succeeded, it confirms that remote clients will now route Internet traffic through the internal corporate network, allowing organizations to maintain monitoring, filtering, and security inspection for remote devices.

This means:

  • Internet traffic from remote clients follows corporate routing policies

  • Security inspection and filtering remain active outside the office network

  • Remote access security governance is strengthened

  • Organizational network policies remain enforced for remote devices

Monitoring this stage ensures that your traffic routing configuration is not only deployed but actively protecting remote endpoints across your environment.

Controlling Internet Traffic Routing for Remote Clients with Microsoft Intune - Fig. 07

Why This Validation Matters

Monitoring the deployment status ensures that the Internet traffic routing policy is correctly applied to remote Windows devices.

This confirmation helps verify that:

  • Remote clients follow the defined traffic routing behavior

  • Corporate security inspection and monitoring remain enforced

  • No deployment failures or unsupported devices exist

  • Remote access policies are consistently applied across managed endpoints

Validating deployment ensures that your configuration is not only created but actively protecting remote devices in your environment.

Client-Side Verification via Event Viewer

After the device synchronizes with Intune, you can perform a client-side verification to confirm that the policy was successfully applied.

Windows records Intune policy processing events locally, allowing administrators to validate enforcement directly on the device.

How to Verify

  1. Open Event Viewer on the target device

  2. Navigate to:

Applications and Services Logs Microsoft → Windows → DeviceManagement-Enterprise-Diagnostics-Provider → Admin

  1. Select Filter Current Log

  2. Look for Event ID 813 or Event ID 814, which indicate successful processing of Intune configuration policies

  3. Review the event details to confirm that the traffic routing policy was applied successfully.

Pro Tip

Match the event timestamp with the device’s most recent Intune sync to confirm when the policy was evaluated.

Event IDs 813 and 814 are reliable indicators that the configuration policy was processed by the MDM engine.

Why This Matters for Remote Access Security

Remote devices frequently connect from home networks, public Wi-Fi, or unmanaged environments.

By enforcing centralized Internet traffic routing, organizations can:

  • Maintain visibility over remote network activity

  • Ensure corporate security inspection remains active

  • Apply firewall and filtering policies outside the office network

  • Reduce exposure to untrusted networks

This configuration helps ensure that remote access does not weaken the organization’s security posture.

Key Takeaway

Security does not stop when users leave the office network.

By controlling how Internet traffic is routed for remote clients using Microsoft Intune, organizations can maintain consistent security policies across all managed Windows devices.

A single well-configured policy can ensure that remote connectivity remains secure, monitored, and governed wherever users work

More Information

For additional technical details, official documentation, and deeper insights into this policy and related Microsoft Intune concepts, refer to the Microsoft Learn resources below.

Thank you!

🖥️ Ricardo Barbosa

🎖️ Microsoft MVP | 📘 Microsoft Certified Trainer (MCT)

☁️ Intune & Cloud Architect |💼 Technology Director at Altelix.com

Originally published on LinkedIn · March 12, 2026 · read the original article
Tags:
MicrosoftIntune
EndpointManagement
Windows11
DeviceManagement
ModernWorkplace
MEM
ITPro
ZeroTrust
MVPBuzz
Keep reading

The full Hardening Windows Endpoints series

One control at a time, with the exact policy paths, the detection and remediation scripts, and the reporting to prove it worked across the fleet.

Browse all articles
Need a hand

Rolling this out across a real fleet?

Reading the guide is the easy part. Designing it for thousands of devices, piloting it without breaking production and proving compliance afterwards is the hard part. That is what we do at ISolutions CloudX.

Talk to ISolutions CloudX

Written by Ricardo Barbosa, Microsoft MVP and MCT. New guide every Wednesday and Friday. Follow on LinkedIn to get the next one.

Posts Sugeridos

Securing Remote Clients: Controlling Internet Traffic Routing with Microsoft Intune | CyberCloudOps Blog