This paper will focus on Identity Services Engine (ISE) ability to determine the endpoint state by doing a posture assessment. Before the release of ASA 9.2.1 VPN users requiring posture functionality required an Inline Posture Node (IPN) between the VPN infrastructure and the LAN protected network. With the release of ASA 9.2.1 we now have the ability to enforce policy the ASA and ISE has the ability to send a “policy push” after a posture assessment has taken place.