Hi there,
You can configure the ACS to send back the Service type Outbound to allow only VPN access:
http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/mgaccess.html#wp1070306
"Service-Type 5 (Outbound)—Denies management access. The user cannot use any services specified by the
aaa authentication console commands (excluding the serial keyword; serial access is allowed). Remote access (IPSec and SSL) users can still authenticate and terminate their remote access sessions. "
This attribute is configured under Policy Elements.
Let me know if it helps.