- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-17-2018 10:39 AM
I'll give it a shot. What I meant with my user centric comment was that in the group mapping configuration, there are options for user attributes, but not computer (Primary Username for example). Since the computer isn't actually doing the authenticating, I wasn't sure this would work.
I've been looking at this: https://researchcenter.paloaltonetworks.com/2015/06/byod-makes-you-productive-and-its-also-why-your-... which says: GlobalProtect can also be used to perform Host Integrity Posture (HIP) checks which sounds like another way to go. I don't think that i could use the domain membership thing, but maybe something else that would be specific to machines that we provide. My main thing is, I want to prevent personal computers from connecting.