A transit Workspace ONE Access connector stays disconnected from the Access tenant after the city proxy began SSL inspection. Outbound TCP 443 from the connector VM is permitted. What should the administrator check next?
Select an answer to reveal the explanation.
Short Explanation
The Access connector is a trusted courier to the SaaS tenant. A proxy that peeks inside TLS swaps the certificate mid-route, so the courier no longer trusts the door even when port 443 is wide open. Exempt those FQDNs from inspection or give the connector the proxy CA.
Full Explanation
Workspace ONE Access Connector requires outbound HTTPS to the Access tenant and validates the tenant TLS certificate. SSL inspection that intercepts that path presents a proxy certificate the connector does not trust, which looks like a persistent disconnect even when TCP 443 is allowed. NSX-T distributed or gateway firewall, identity firewall, Guest Introspection, and Carbon Black Cloud do not broker the connector-to-SaaS control channel. Configure a proxy bypass for the documented Access destinations or install the enterprise proxy CA in the connector trust store, then retest connector health.