We recently had an issue where a user brought their laptop in from home and plugged it into the network, attempting to get internet access. I know on a port level I could setup MAC restrictions, but I was wondering if there was a way that I could prevent a non-compliant machine from even getting access to our network in the future? We currently run all Windows 7 client machines and I'd like to simply tell it "if not Windows 7, no access", but not sure exactly how to go about that. We are running an AD environment, 2008 and above Windows Servers.
I thought maybe NAP would work, and it appears to have a setting for WinXP (and one for Win7), but it allows me to disallow/allow access based on if it is up to date, if virus protection is on, etc, not if it's Windows XP itself. Is there a way that I could disable anything but what I specify from getting access to the network like this?
Thanks in advance for your help!