Elections staff who launch an application from a risky network should see a deny with a custom message. Which control provides that user-facing response?
Select an answer to reveal the explanation.
Short Explanation
A custom deny is a polite locked door with a sign, not a silent packet drop or a wipe. Access policy deny plus branding shows elections staff why SSO stopped. Carbon Black isolate and NSX drop never print that Hub message.
Full Explanation
Workspace ONE Access policies can deny authentication for a network range and present a custom message through Access branding. That is the user-facing control for SSO applications. Carbon Black Cloud isolation and NSX-T drops do not render an Access deny page. An enterprise wipe is a UEM device action, not the correct response to a risky-network SSO attempt.