I have an interesting use case and looking to see if this is even possible. We have two SSIDs broadcasting on our MR33 tagged Corp VLAN 30 and Employee VLAN 40. I have RADIUS authentication set up for the Corp SSID and use an AD security group to grant access to corp staff. Is it possible to segregate the access using the same RADIUS server? For instance we want all employee traffic on VLAN 40 since we have different traffic shaping rules and restrict access to certain server resources, but if I add them to the security group they could theoretically access the Corp SSID as well. Thoughts on how to do this? We are running Win Server 2016 AD and a local NPS to provide RADIUS.