Wanted to throw this out there & see if anyone has been in a similar situation:

Overall: We need to control only domain/managed laptops from connecting to our VPN. I'm doing this via SCV checks...