A water utility must enroll corporate laptops in Workspace ONE while keeping SCADA historian hosts isolated. What firewall stance should the security administrator take?
Select an answer to reveal the explanation.
Short Explanation
Enrolling office laptops is not a hall pass for the plant floor. Keep the OT VLAN away from UEM and Access, and enroll only the corporate laptop VLAN.
Full Explanation
Enabling Workspace ONE for enterprise endpoints does not require OT or SCADA networks to reach UEM or Access. Deny the historian VLAN toward those management planes and allow enrollment only from the corporate laptop VLAN. NAT into the enrollment segment or any-any from historians expands the OT attack surface without serving the Workspace ONE enablement goal.