Device Isolation Settings Questions

Hello All,

Questions regarding Endpoint Policies Device Isolation Settings. Need some clarification and if anyone out there is using this settings

The description states for Device Isolation - Allow computers to isolate themselves on red health

 Note: If a computer has red health, it will isolate itself from the network. It will still communicate with Sophos Central.
1. Does that mean if the computer is not updated with the latest version will the device auto isolate?
2. This seems like it would be a pain in the butt if you have many nodes. I'm guessing users will call and say I cant get email or access the internet 
because the agent is not updated
3. Does anyone use this feature at all and how does it affect your day to day support of many nodes
Thoughts on this ...thanks

