You need to create a group policy for each group of different rules that you want. Then log in via VPN as the user account. After this they appear in the portal. Once they appear their apply the group policy to them.
The setting will now stick each time the user logs in.
The Group Policy is applied to the device, not the user - generally this is by MAC address. Note that the MAC address will be that of the VPN adapter on the client, so different to its Ethernet adapter. Thus if a client connects via Client VPN and directly to the MX (e.g. in an office) then it will appear twice in the client list - once for each MAC address, and so could have a different Group Policy assigned for each.