Would anybody know of a guide that details how to configure a post authentication epa check for domain join that will prevent access to the VPN but allow fallback to ICA (storefront). I have this configured via the classic method in the session policy but want to migrate it to an nfactor flow. Not sure how to do the fallback piece.