Re: Web filtering for specific AD groups using SSO
I don't know any workaround for your problem, you cannot leave the address group field empty, but we have a similar situation within a citrix environment. The way I solve this is to create seperate rules for the different SSO Groups. Source is "citrix address group" "sso user group 1, 2, 3, ..., X", destination is WAN. And the last policy below all others is: source "citrix Address group" "sso group All Users". -> I used an AD Group, where all our AD Users are member of. So every AD user that doesn't belong to any of the upper AD Groups, belogs automatically to the last policy rule. So you can specify seperate Webfilters, Ports, destinations for one or more special SSO groups and all the rest belongs to the "all users" rule.