Contractors on the civic WLAN must land in a restricted role and VLAN via AAA. How should that be enforced?
Select an answer to reveal the explanation.
Short Explanation
Do not trust contractors to pick the right SSID like it is a lunch menu. Let RADIUS hand back the role and VLAN so RBAC does the steering. Domain-admin Wi-Fi for vendors is how audits get exciting.
Full Explanation
Role-based access on enterprise WLAN commonly uses RADIUS attributes to assign roles, ACLs, or dynamic VLANs based on authenticated identity. That enforces contractor restrictions consistently instead of relying on user SSID selection. Privileged profiles for convenience and disabled accounting undermine least privilege and accountability.