Just-in-time provisioning from the statewide identity provider creates Access accounts for every student, flooding the school-district directory. What should the administrator tighten?
Select an answer to reveal the explanation.
Short Explanation
JIT should not photocopy the entire student roster into Access. Filter claims and groups at the IdP so only the intended staff land.
Full Explanation
Just-in-time provisioning from a federated IdP can create Workspace ONE Access users for every assertion that arrives. Claim and group filters limit which identities are provisioned. NSX identity-firewall timers, Carbon Black Cloud groups, and Distributed Firewall default-allow do not scope JIT federation.