Here's the scenario - the customer management would like to restrict the corporate users on using non-domain laptops when connecting to the corporate network. Only domain managed devices can be allowed, non-domain laptop should be restricted even the corporate user entered the correct corporate domain credentials to the captive portal, their access should be denied because the device is unmanaged by the AD.
Can we implement this kind of use case? are there any option on Identity Awareness that can we install like an agent and check the user endpoint if part of AD or not?