Hello Howard,
You can use the RegMonitor for block machines out of company domain. I made this same configuration in this week, the parameters configured were:
(RegMonitor
:type (plugin)
:parameters (
:string ("HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\History\MachineDomain=yourdomain.com")
:begin_admin (admin)
:send_log (alert)
:mismatchmessage ("You message for users")
:end (admin)
Don't forget configure this policy in SCVPolicy field. About macbook, according sk110975 you cannot use SCV file for macOS systems. If necessary, you have to use Compliance Blade prior to VPN connection.
Note to use Compliance Blade is necessary an adittional license for management server.
Thank you, good luck!
Alisson Lima