Employee With Personal Device on Internet-Only VLAN

This is an example workflow for an employee using a personal device on the secure network, but is limited to an Internet-only VLAN. The employee authenticates to an Active Directory group, and the device type split is managed with a filter, which moves the user to the Personal Device workflow branch if they are a member of a specified AD group. The user is asked to acknowledge a BYOD use policy before being moved to an Internet-only VLAN with a certificate that is limited to 30 days access.

Example Workflow for Employees with Personal Devices on Internet-only VLAN