Conditional Launch restricts app usage by incorporating the Jamf Security Cloud device risk score:
Users sign into corporate apps with their work credentials on their personal devices.
Before users are granted access, Conditional Launch policies prompt the user to install Jamf Trust on their device.
Jamf Trust installs seamlessly with users' work credentials and begins assessing device telemetry. Risk factors are continuously evaluated in real time.
Telemetry is synthesized by Jamf Security Cloud to understand the overall risk posture of the device.
Integration with Microsoft Intune allows Jamf Security Cloud to share the device risk status, which can then be used to enforce Conditional Launch policies.
When the risk level rises, user privileges can be restricted to prevent corporate data from being exposed to malicious parties.
These App Protection Policies can be deployed alongside Conditional Access which triggers the UEM solution. To configure App Protection Policies on your unmanaged Microsoft Intune devices, see the Add Mobile Threat Defense apps to unenrolled devices documentation from Microsoft.