Block jailbroken and rooted phones

Block jailbroken and rooted phones

I saw an option to block jailbroken phones.  How do we block rooted phones with MDM in desktop central? 

What happens to the device if they violate a policy setting?  Does it go out of compliance and remote wipe, etc?  Are there settings for that?
                New to ADManager Plus?

                  New to ADSelfService Plus?