If you can reach internal resources from a remote connected device over the device tunnel, they should be able to manage out to that endpoint. There are a few things that need to be considered, however.
First, the device tunnel is typically only configured to route to specific internal hosts. Ensure that you are trying to manage out to the VPN client from a host listed in the device tunnel's routing table.
Also, ensure the Windows Firewall on the endpoint is configured to allow traffic from the internal network.
You may have to enable firewall logging and look through the logs to see if any traffic is being allowed or denied. You might also want to take a network trace on the management server/workstation and the endpoint at the same time to see what's happening on the wire.
Hope that helps!