The TMWS Agent app is used for the virtual gateway. The on-premises gateway does not support the app.
Deploy the TMWS Agent app onto individual iOS or iPadOS devices, or use Microsoft Intune to deploy the app to the managed mobile devices of your organization in batches for centralized device management.
Once deployed,
  • The TMWS Agent app is installed on the device.
  • A configuration profile is added to enforce the use of a PAC file for HTTP/HTTPS traffic forwarding to TMWS.
  • The TMWS certificate is deployed to the device.


  1. Go to AdministrationSERVICE DEPLOYMENTEnforcement Agent.
  2. On the Enforcement Agent page, configure the following settings:
    • Agent platform: Select iOS/iPadOS.
    • Hosted PAC file: Select a PAC file from the drop-down list.
      TMWS provides a default PAC file for use on iOS/iPadOS. The PAC files already created on the PAC Files screen are also listed. For more information on adding a PAC file, see PAC Files.
      Once selected, the PAC file will be used in the TMWS Agent app.
      If you modify the content of the selected PAC file or choose another PAC file, it will take a few minutes for the update to take effect. If there are users who encounter network connection issues because of this, instruct them to disconnect and re-connect in the TMWS Agent app.
    • Company token: Click Generate Company Token to generate a token if you deploy the TMWS Agent app through Microsoft Intune.
      This action generates a new token for the TMWS Agent app on both iOS/iPadOS and Android. You need to update the token in Microsoft Intune for the app on both platforms.
  3. Choose one of the following to deploy the TMWS Agent app to the required Apple devices.