Just to expand on this then as you are looking at using Active Directory joined machines then after setting up the IA Collectors then make sure that in the Access Roles that you create that not only do you specify Users but also specify Machines.
The Default Machines setting is Any Machine. If want to enforce AD joined machines then make sure that use the
Specific machines/groups
rather then
Any Machine.
That way the machine must be part of the group(s) that add so would have to be AD joined.
So would be controlling to users over the VPN to specific resources and would have to be from specific machines.