City attorneys must receive a VPN profile only while their phones remain compliant, and jailbroken devices must lose that tunnel. What should the administrator configure?
Select an answer to reveal the explanation.
Short Explanation
A privileged VPN is a badge that should snap off the moment the phone is jailbroken, not a sticker you leave on forever. Tie the VPN profile to compliant devices, then let compliance yank it when posture fails. A forever-on profile keeps the tunnel up on the exact phones you wanted to cut off.
Full Explanation
Workspace ONE UEM can combine profile assignment with compliance so privileged payloads such as VPN are present only on devices that meet posture rules. Jailbreak or root typically marks a device non-compliant, and compliance actions can block apps, notify, or remove access to those profiles. A forever-on VPN assignment, a Carbon Black Cloud allow list, or an NSX-T rule that ignores MDM state would leave the tunnel available on compromised phones.