Per App VPN on Mobile - DNS Question

Does per-app VPN ZPA on mobile constantly intercept DNS with ZPA (always on) or does the DNS interception only start occurring when a VPN application is launched?

The VPN profile would always be “on” in this scenario, but the VPN applications would not always been running.

When the app Is running, all traffic from the App will be subject to “VPN” (inc the DNS). The OS will follow defaults for other apps/traffic.

To clarify, if the app is always signed in, does it keep inspecting if the app specified in the profile is not open? I ask because the VPN profile only shows with the apps configured are open.

This makes me think the inspection is continuous when the apps configured are open, but not possible when they’re closed.