Hi Mark Surprisingly it doesn't. We tested this, both with AD policy on the back end LDAP AD, as well as trying to enforce a group policy on the MX. Everything works when a user tries to reconnect, which is good, but Cisco seems to have overlooked the need to give someone a push. Whilst we can work around this, it does seem somewhat of a basic requirement that you would expect to find on the units. Steve
... View more