Everything about this new flow works great, however it appears to not be able to evaluate device compliance in the same manner as Company Portal can.
As an example, we have this MAM policy...
App PIN when device PIN is set: Not required
So this usually works well for personal devices with corporate apps, where a PIN is required to access the corporate app.
However, for a supervised device, this doesn't seem to be evaluated after the first launch, even though the device already has a PIN set. After 30 minutes, our MAM policy rechecks access requirements, and unfortunately, prompts the user to enter a PIN for the app. Before, this would not be the case, and the user would only need to unlock the supervised device once with a device PIN, then launch apps without having to enter the app PIN a second time.