Hello!
I have a customer who is extensively using Identitiy based Policies for its users and now faces a challenge that I don't see a good solution for (yet):
They have a bunch of users with devices (Ipdas/IOS) that have no connection to the AD, but still need their own set of rules in the policy.
First I suggested to assign them a specific subnet, but it seems that is not possible, as they have to use a WiFi SSID which is shared with other users and devices.
Having them authenticate with machine certs is also no option here according to the customer.
Now the only option that comes to my mind would be the usercheck page where they can log in to get access. This should work with local (=non-AD users), right?
Would there be any other option I just missed? Something more transparent for the user maybe? Some other way to have them authenticate with a local account that I do not think of yet?
Any input on this would be great!
Cheers,
Alex