A council member’s unmanaged personal phone requests the high-trust finance SSID. Policy requires MDM for that SSID. What should the design do?
Select an answer to reveal the explanation.
Short Explanation
High-trust SSIDs are the vault; unmanaged phones without MDM do not get the vault combination. Point them to a restricted guest or contractor network and keep finance locked down. Promises, emailed PSKs, and blind spots are not controls.
Full Explanation
BYOD on sensitive municipal SSIDs typically requires MDM or equivalent management for configuration and compliance. Unmanaged devices should be directed to lower-trust guest or restricted networks rather than high-trust staff SSIDs. Temporary promises or shared secrets do not satisfy that policy boundary.