Sorry, but I still didn‘t get the point. What do you mean by „So in this case I can solve this issue by making every client on the VPN not able to talk to said endpoint over group policy but I have to set this rule for every client in group policy to not talk to the endpoint.“? you don‘t have to do it for every client themselves. That‘s what Group Policy is meant for?! if you want to make specific policies for every client, just go for dedicated Group Policy for every client. These could be dynamically assigned by ISE e.g.
... View more