City Workspace ONE Access uses a hybrid LDAP bind from the cloud tenant through ExpressRoute to on-premises domain controllers. After a WAN flap, directory sync fails. An engineer wants to regenerate IdP metadata immediately. What should the administrator check first?
Select an answer to reveal the explanation.
Short Explanation
After a WAN burp, look at the road before reprinting the passport. Access still has the same IdP metadata; it just cannot reach the DCs. Prove ExpressRoute and LDAP reachability first — regenerating metadata is a later, rarer fix.
Full Explanation
Hybrid Workspace ONE Access directory integrations depend on network reachability from the Access service or Access connector to on-premises domain controllers, typically over ExpressRoute or VPN. A flap that breaks that path fails bind and sync without corrupting IdP metadata. NSX-T identity firewall groups, Carbon Black Cloud, and local-account fallback do not restore that hybrid identity path. Confirm routing, DNS, and LDAP ports across the hybrid link, then rebuild metadata only if trust material is actually invalid.