A water-utility uses a public-cloud directory as the Workspace ONE Access identity provider, while NSX-T identity firewall still binds on-premises Active Directory. The same operator is in SCADA-Operators in AD and scada-ops in the cloud directory, so Access and IDFW disagree on who may reach a jump VM. What should the administrator do?
Select an answer to reveal the explanation.
Short Explanation
Two directories with two spellings of the same crew is a split nametag. Access and IDFW will never agree until someone maps those groups or uses one source of truth. Don't pick a winner or expect Geneve to merge identity.
Full Explanation
Workspace ONE Access and NSX-T identity firewall each evaluate groups from the directory they are bound to. When a public-cloud IdP and on-premises Active Directory use different group names for the same people, Access allow decisions and IDFW rules diverge. Carbon Black Cloud and overlay networking do not reconcile those mappings. Align group names, use a consistent identity source, or maintain an explicit mapping so both products authorize the same operator set.