A transit authority places Workspace ONE Access behind the civic DMZ. How should the security administrator enable the Access connector without exposing it to untrusted networks?
Select an answer to reveal the explanation.
Short Explanation
The Access connector is a doorman, not a public lobby. Give it HTTPS 443 so identity traffic can flow, and keep SMB and RDP off the internet-facing side.
Full Explanation
Workspace ONE Access and its connector require HTTPS for authentication flows. File-sharing and remote-desktop ports on the connector host are not identity-enablement paths and must stay blocked from untrusted networks. SaaS branding does not justify disabling the host firewall or publishing SMB or RDP toward the DMZ.