Good evening...
Outside of using Cisco ISE and using up expensive advanced licenses, is there away to allow users to connect via Cisco Anyconnect on their pc or laptop, but keep them from setting it up on their phone or tablet? I would like to offer two different groups based on the agreed access level. "corporate provided laptop" or "corporate provided laptop and mdm managed personal device". Currently, using the old cisco vpn client, you had reasonable assurance that if someone didn't have the profile they couldn't set it up on whatever device they wanted.. With anyconnect, it seems hard to limit what devices it can be configured on. My only thought is that by utilizing certificate based authentication, not enabling scep on the ASA, the laptop gets it's certificate when it's imaged and joins the domain. The personal device get's its certificated through the MDM and it's scep setup.... As anyone ran into this issue?
Thank you,
Raun