There are three ways to restrict access to apps on users' devices using your organization's access policy with Jamf Connect's Zero Trust Network Access. Each of these access controls protects the apps in your environment from being accessed by devices that may pose a security threat.
- Access requires device to be managed —Enable this feature to prevent unmanaged devices from accessing the application. When enabled, you can configure a push notification to inform users of unmanaged devices why their access was denied. The device management state is determined by your configuration's UEM Connect synchronization. Devices actively enrolled in the connected UEM are considered managed, as long as they have checked in with the UEM within the defined device check-in threshold. All other devices are considered unmanaged. If UEM Connect is not configured or fails, your device management state may be inaccurate.
- Access requires device risk validation —Enable this feature to prevent devices with a specified risk level (or higher) from accessing the application. When enabled, you can set the risk level and configure a push notification to inform the user when and why their access is denied.Note:
This option is only available for managed Apple devices with a Network Threat Protection profile.
- Access requires Jamf Trust to be enabled —Enable this feature to continuously enforce the access rules for an application. When enabled, the user cannot access the application on their device while the Jamf Trust app is disabled.
Requirements
A defined access policy for the app you want to secure
- In the Jamf Security Cloud portal, navigate to .
- Choose the app you want to edit access to, and click Edit.
- Select the Security tab.
- In the Device-risk based access control section, use the switch to enable this control.
- Select a risk level from the Deny access to devices starting at the following risk level menu. Devices with the selected risk level (or higher), will be denied access to the app.
- (Optional) Select the Notify users when access is denied checkbox to enable push notifications to users' devices when access is denied due to risk level.
- In the Device management state-based access control section, use the switch to enable this control.
- (Optional) Select the Notify users when access is denied checkbox to enable push notifications to users' devices when access is denied due to management status.
- In the Restrict access when Jamf Trust is disabled section, use the switch to enable this control.
- (Optional) Select the Notify users when access is denied checkbox to enable push notifications to users' devices when access is denied due to Jamf Trust being disabled.
- Click Save.
Devices are prevented from accessing your organization's apps unless they meet your chosen criteria.