I tried introducing machine authentication function on ISE in order or separate authorization policy each for the person whose pc name is registered in AD and not. I know that we can use the attribute "Wasmachineauthorized" to realize my wish. Howev...