INTUNE-012: Conditional launch settings
- Plataforma
- Entra ID / M365
- Categoría
- Intune / Endpoint Management
- Severidad
- Medium
- Pilar de Zero Trust
- Devices (peso 3)
- Fixtures de referencia
- 3
- Cobertura de ramas
- Observada: los fixtures prueban los veredictos que ejercitan
- Procedencia
- baseline
Qué comprueba
Conditional launch settings within application protection policies define the conditions under which a managed application can be launched, such as minimum OS version, maximum allowed threat level, or jailbreak/root detection. Without these settings, compromised or outdated devices can access corporate data through managed applications even when the device itself is insecure. These controls provide a critical last line of defense for data protection.
Valor recomendado
Block access on jailbroken/rooted devices; require minimum OS version; block access when device threat level is high
Remediación
Review and update the conditional launch settings in each application protection policy to block app access on jailbroken or rooted devices. Configure minimum OS version requirements that align with vendor-supported versions and set maximum device threat level thresholds that integrate with your Mobile Threat Defense solution. Test the conditional launch settings with a pilot group before broad deployment to ensure that legitimate users are not inadvertently blocked.
Veredictos probados con fixtures
Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.
| Escenario | Veredicto esperado |
|---|---|
| clean | PASS |
| known-bad | WARN |
| throttled | Not Assessed |
Mapeos a marcos de referencia
- NIST SP 800-53
- AC-19