I have defined a policy set with below flow
-VPN user initially hits the posture Unknown rule and redirection URL is pushed
-Endpoint gets complaint and ISE issues CoA
-If the endpoint belongs to an AD group referenced in the authorization profile then it should get access otherwise the endpoint should hit the default Deny rule.
The behaviour I am seeing is when an endpoint does not belong to an AD group ISE directly sends a CoA Disconnect. If user belongs to an AD group then CoA Reauth is sent.
Shouldn't I expect ISE to send a CoA Reauth after endpoint gets complaint whether user belongs to a group or not ? If user does not belong to an AD group it should the Default Deny rule after a Reauth.

