School-issued laptops are Intelligent Hub managed. Teachers roam into a cloud VDI desktop that is not an NSX-T prepared workload. Staff report Hub still blocks SaaS when compliance fails, and they expect the on-premises Distributed Firewall to follow the laptop into the cloud VDI. What should the administrator explain?
Select an answer to reveal the explanation.
Short Explanation
Hub's compliance leash travels with the enrolled device; NSX DFW stays in the prepared datacenter. Cloud VDI that is not on that fabric will not inherit county DFW, but Access can still refuse SaaS if UEM says the laptop is non-compliant. Use the right control for where the session actually lives.
Full Explanation
Workspace ONE UEM compliance is evaluated on the enrolled endpoint and can continue to gate Workspace ONE Access regardless of whether the user is on campus or in a cloud VDI client. NSX-T Distributed Firewall is realized only on prepared transport nodes in that NSX fabric; it does not follow a laptop into an unprepared cloud VDI. Carbon Black Cloud and Guest Introspection also do not stretch on-premises DFW into that VDI. Troubleshoot by identifying which plane is in path: UEM and Access for the device and IdP, NSX DFW only where the workload is prepared.