Which three steps need to be completed to configure Identity Bridging for an SAML application on the VMWare UAG? (Choose three.)
Correct Answer: ACE
To configure Identity Bridging for an SAML application on the VMware UAG, the following steps need to be completed: First, an identity provider must be configured and the SAML metadata of the identity provider saved. Second, you need to configure a Web Reverse Proxy for Identity Bridging from Certificate to Kerberos. Finally, the UAG certificate must be pinned to the SAML provider to establish a secure connection. These steps are essential for setting up Identity Bridging which enables SAML assertions to be correctly processed and verified by the UAG.
Refer to the ACME Financials design use case.
ACME Financials Design Use Case -
1. Introduction
1.1 Business Overview
ACME Financials is an investment firm that has established itself as a leader in USA's fast-moving financial asset management market and has around 1000 employees.
ACME plans to transform its end-user computing resources to the digital workspace. ACME wants a secure platform that is available from any device and from anywhere, as well as a solution that reduces operating costs.
ACME's major business driver for the digital workplace is to enable employees to work remotely, and to enable the secure access to all of its resources from anywhere and any device while enhancing security with multi-factor authentication. The solution should support its BYOD strategy and let remote employees use their own laptop, desktop, or mobile device to access the resources from any location.
ACME also wants to remove the need to supply and manage desktop hardware to external contractors. Because financial data is highly sensitive, the firm needs a technology that would protect customer and other critical information - even when accessed on a mobile device. ACME is looking to improve the security of the desktop and application platforms across the enterprise. In addition to using endpoint security tools and multi-factor authentication, ACME insists on using additional security and controls to provide the highest level of security and protection to services and applications.
ACME currently uses a VPN-based remote access solution. ACME would like to remove additional components that add support or management complexity, and device dependence for remote access users. ACME is looking to achieve the same access to virtual desktops and Windows 10 or mobile applications, both inside and outside of the ACME enterprise network.
ACME is very keen on enforcing standardization to keep the IT infrastructure as consistent as possible. IT wants to use standardized versions of Windows
(Windows 10), consistent configurations, and application delivery from a central source. All while maintaining the compliance of every device that requires encryption, password and PIN protection, as well as update -and anti-virus control.
To simplify and standardize desktop and application delivery, ACME wants to offer a service catalog based approach based on ACME IT standards. This will allow
ACME to effectively deliver and manage resources, allowing IT to deliver device and application services that meet business and technical needs, while maximizing the use of shared IT computing resources.
Additional Facts -
✑ Speaking to the developers revealed that most apps are standardized apps from public app-stores, but ACME uses some their in-house developed, critical mobile apps, where some of the developers have already left the company, so that they cannot be rewritten in a short amount of time.
✑ To reduce operating costs, ACME has already moved to Office 365 and is currently running a few migrations from on-premises to the cloud for other applications.
ACME's IT says that it is a Microsoft Windows only shop, but the assessment shows that currently most of the managers are using Apple devices.
✑ ACME currently uses directory services and two-factor authentication mechanisms (Radius) for internal and external access. ACME requires to support Single
Sign-On (SSO) integration with their current authentication solutions. They also require to use SSO whenever possible, as they do not believe in having multiple user accounts and passwords for their end users.
✑ ACME wants the solution to provide mechanisms to provide a secure e-mail solution to any device that complies to global security standards even for BYO devices.
1.2 High Level User Classification
✑ 680 Office workers (call center, corporate and office administrators) use standardized PCs or Thin-Clients to access ACME's core apps and tools.
✑ 240 Remote-office workers use the company's CYOD initiative and use these devices (Notebooks, Convertibles, Tablets, Android phones) to access their apps and tools from remote.
✑ 30 Executives use Apple Mac Books as well as iPhones and iPads to work on- and off-premises.
✑ 80 IT -admins and software developers are using high-end workstations with administrative access.
1.3 High Level Application Assessment
✑ ACME currently has 261 applications, of which 186 are based on Microsoft Windows.
✑ Today, users are allocated applications via AD group membership.
✑ 75 applications are either web-based or SaaS-based, including Office 365.
✑ A major incident recently meant sales workers were disappearing suddenly along with their data and laptops on some new colonies.
✑ Any external access should require multi-factor authentication. Access from the internal network should work seamlessly with SSO for the core applications.
High-security applications also require MFA from internal access.
✑ The address ranges of the HQ datacenter are as follows:
â—¦ 172.16.0.0/16 internal
â—¦ 80.34.57.20/21 external
2. Initial Stakeholder Interview Findings
In addition to the goals summarized in the previous section, the following are findings from initial interviews with the key stakeholders and an analysis of their service level agreements.
1. The design must use the F5 Loadbalancer and should be as redundant as possible.
2. Qualified IT personal is hard to find these days. If possible, reduce operational costs and try to automate or outsource basic IT-tasks.
3. ACME is very particular about meeting the go-live date. If there are unforeseen delays, the project may not be delivered for the required go-live date.
ACME requires multi-factor authentication for application access from external networks. This has been established with a default access policy that incorporates multi-factor authentication. However, some users complain that they do not want to enter the multi-factor authentication when accessing the applications from within the company network.
How can the user experience be improved?
Correct Answer: D
To improve user experience while maintaining security, the correct approach is to create an access policy that does not require multi-factor authentication when accessing from the internal network range. The internal network range for ACME's HQ datacenter is defined as 172.16.0.0/16. By specifying this range in the access policy, internal users can access applications seamlessly with Single Sign-On (SSO) while ensuring that multi-factor authentication is still enforced for external access and high-security applications. This approach aligns with ACME's requirement to balance security with user convenience.
An administrator plans to create a staged enrollment of devices in Workspace ONE UEM.
What is a possible solution that enables the administrator to onboard devices one department after another?
Correct Answer: C
Restricting enrollment to Assignment Groups is a suitable solution for onboarding devices one department after another. This method allows the administrator to control which devices can be enrolled by creating specific groups for each department and then enabling enrollment for those groups in a staged manner. Device Restriction Policy and Access Policy do not provide the same level of granularity for department-specific onboarding, while restricting enrollment to Configured Groups is generally less specific compared to Assignment Groups which are more finely tuned to such use cases.
An administrator wants to integrate VMware Identity Manager as a Federated Identity Provider for AD FS.
Which two steps need to be completed? (Choose two.)
Correct Answer: AB
To integrate VMware Identity Manager as a Federated Identity Provider for AD FS, two main steps need to be completed. Firstly, configuring VMware Identity Manager as a Service Provider for AD FS is essential. This establishes the connection allowing AD FS to recognize VMware Identity Manager as an entity that it will authenticate users for. Secondly, creating a VMware Identity Manager claims Provider Trust in AD FS is necessary. This involves setting up the trust relationship where AD FS accepts authentication assertions from the VMware Identity Manager. These steps ensure the correct communication and trust between AD FS and VMware Identity Manager.
An administrator wants to migrate a System Center Configuration Manager (SCCM) collection into a Ñо-managed stage in Workspace One UEM. Workspace ONE
AirLift does not display the collection as mapped.
What is most likely the issue?
Correct Answer: B
Workspace ONE AirLift will not display a collection as mapped if the collection mapping is removed or if the migration is completed and the ConfigMgr collection is no longer used. This is the most likely reason why the collection is not appearing as mapped.