On wifi, not that I'm aware of.
Out of curiosity, what do you mean they need permissions on Android? Up until the last Android version (Marshmallow), you either gave an app all permissions or didn't install it. To deny network traffic outside of that you basically had to have root access (which is functionally equivalent to jailbreaking).
Google have gone the same way as Apple with Marshmallow though and apps can access internet without permission in the new system - INTERNET is a 'normal' permission automatically granted. [0]
[0] http://developer.android.com/guide/topics/security/normal-pe...
Could a per-app VPN be used to blackhole app-specific network traffic at the VPN server? If so, would this need a third-party MDM solution, or could the native IPSEC client be used?