Why It Matters?
An evolving threat landscape necessitates that sessions are continuously assessed for malware or a degraded security state. Checking for an external endpoint security signal is key to ensure that a session is safe to continue and prevents data exfiltration, network traversal, and other security attack techniques.
What Exactly Does This Policy Do?
This policy helps maintain a zero trust environment by assessing device trust at the beginning of a privileged session, and continuously assessing device trust and terminating the session if the device trust state goes bad.