Thanks for your reply.
I want to give some details of my ongoing deployment.
We use one subnet for all wired and wireless networks so all users including IoT are in one subnet.
All IoT devices use only a wireless network and other users connected on the wire.
So please advise, how can I implement these policies?