Transit helpdesk can reset AD passwords, so password alone is too weak for a VPN-like SaaS app in Hub. What should the administrator require?
Select an answer to reveal the explanation.
Short Explanation
If the helpdesk can mint a new password, that password is a spare house key—not a second lock. Put OTP or a certificate after password on the Access policy so a reset alone cannot open the SaaS app.
Full Explanation
Workspace ONE Access policies can require two authentication methods in sequence on the same rule. Adding OTP or certificate after password closes the helpdesk-reset gap for a high-value SaaS app. Password-only remains a single factor even if the helpdesk verified a caller. Carbon Black device control and NSX identity firewall do not stack Access authentication methods.