Transit Workspace ONE Access policies that should restrict a cloud SaaS to the operations network now match any after the agency moved those operators onto a public-cloud desktop pool. The pool egresses through a new NAT prefix that was never added as an Access network range. What should the administrator update?
Select an answer to reveal the explanation.
Short Explanation
Access network ranges are the guest list at the door. When operators started egressing through cloud NAT, their source IPs were no longer on the list, so the policy fell through to any. Update the ranges — NSX DFW on a different fabric will not fix Access.
Full Explanation
Workspace ONE Access policies can key off network ranges that identify client source IPs. Public-cloud NAT changes those egress addresses, so policies that still list only on-premises prefixes stop matching and may fall through to a broader rule. NSX-T Distributed Firewall, Carbon Black Cloud sensor groups, and Guest Introspection do not define Access network ranges. Add the new NAT prefixes to Access network ranges and bind them to the intended policy.