After the courts case-management URL changes, SP-initiated and IdP-initiated SSO both fail. Which Workspace ONE Access objects should the administrator update?
Select an answer to reveal the explanation.
Short Explanation
SAML is picky about names on the envelope. When the case-app URL changes, update ACS, entity ID, and audience in Access—not an NSX cookie.
Full Explanation
SAML SSO depends on matching Assertion Consumer Service URLs, entity IDs, and audience values between Workspace ONE Access and the application. A URL change requires those federation endpoints to be updated. NSX persistence, Carbon Black Cloud reputation, and Distributed Firewall tags do not repair SAML endpoint mismatch.