Updates appear to be bypassing VPN without permission

A

AC Question

I'm using Samsung J3 devices deployed across our enterprise. We are using NetMotion Mobility V 11.04 to block and allow specific applications and set QoS based on network type. In testing, we are seeing update traffic going around the VPN when on Cellular Data which makes the Android platform fail our security testing. Can anyone provide advice on this? These devices are on Verizon and in-house WiFi. We want to block all updates unless the device is on WiFi.