Is there a way within ACS to restrict a user to a specific VPN group. I know that if authenticated the user locally on the ASA / PIX (ver 7) you can do this with a user attribute.
What I am trying to achieve here is to stop a user jumping into a different group with more rights if they get hold of the vpn client profile