A water utility requires multifactor authentication at the statewide identity provider and a compliant enrolled device before SCADA-adjacent web tools open. How should the administrator layer those controls?
Select an answer to reveal the explanation.
Short Explanation
MFA at the state desk proves who is knocking; Access still checks whether the laptop is a city device. Stack both—do not drop compliance because MFA exists.
Full Explanation
Third-party IdP MFA authenticates the user but does not replace Workspace ONE Access device-compliance evaluation. The operational pattern is layered: MFA at the IdP plus an Access policy that requires a compliant enrolled device. Dropping compliance, substituting gateway geolocation, or trusting a sensor UUID alone leaves device posture unenforced.