Administrators report that some non-compliant devices can still reach private applications. A broad Allow rule precedes device-posture checks in the policy set.
What is the most appropriate next step to satisfy the compliance-before-access requirement?
Submit