- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-09-2025 03:19 PM
You would generally deploy both. Enforcing the VPN connection would accomplish exactly what you're looking for; network connection would be disrupted (minus the exceptions that you configure) if you aren't connected to the VPN. The issue with that is that unless it's paired to Always-On the user needs to take steps to actually get a network connection.
Ease of use would be that you have Always-On enabled so that the VPN connection would just always be connected for the user and they wouldn't have to do anything extra from an issued device. It would also be enforced so that if for whatever reason the connection fails, it isn't allowing unfiltered network traffic to pass through on the device.