The NAC appliance offers a way to check to make sure someone has updated their PC with the latest virus definitions. They do not however, have a way to check to see if someone has done a full scan of their PC withing the past X number of days.
Here is what I did:
Mcafee writes to a file called ondemandscanlog.txt. this file is updated each time the user does a scan of their PC.
You can setup the clean access manager to check to make sure that file has been modified within the past x days, which will indicated that a scan has been performed.
The file is located at:
C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection
on an XP machine
and on Vista computers, its here: c:\ProgramData\McAfee\DesktopProtection\ondemandscan.txt