Library volunteers authenticate with a third-party social identity provider that must never single-sign-on to the finance application. What should the administrator configure?
Select an answer to reveal the explanation.
Short Explanation
Volunteer badges open the stacks, not the treasurer's vault. Scope Access so the social IdP is valid only for volunteer apps.
Full Explanation
Which identity provider is accepted for an application is a Workspace ONE Access policy setting. Scoping the social IdP to volunteer apps and excluding finance prevents that federation path from SSO to finance. Distributed Firewall, Carbon Black Cloud device control, and shared passwords are not IdP-scoped SSO controls.