Public-health Workspace ONE UEM cannot reach the on-premises CA or LDAP after a datacenter ACL change. The cloud UEM console itself is healthy. What should the administrator trace?
Select an answer to reveal the explanation.
Short Explanation
ACC is the on-prem mailman for UEM — the cloud console stays pretty while the mailman cannot reach LDAP or the CA. Trace outbound 443 from ACC to SaaS and the inside legs to AD and the certificate authority. Don't rebind NSX Manager's IDFW directory as if it were UEM.
Full Explanation
Workspace ONE UEM uses AirWatch Cloud Connector as the on-premises broker for directory, CA, and related enterprise services. The SaaS console can remain healthy while ACC outbound HTTPS to UEM or ACC paths to LDAP and the CA are blocked. NSX-T Manager's identity-firewall directory binding, Carbon Black sensor groups, and Distributed Firewall FQDN profiles are not the UEM on-prem connectivity path. Verify ACC cloud connectivity and the Connector-to-DC and CA legs, then retry directory and certificate workflows.