A network access control policy server that decides whether a device or user is allowed onto a network and what access they receive once admitted. It answers authentication and authorization requests from switches, wireless controllers, and VPN gateways, identifies connecting endpoints by observing their network behaviour, and checks their security posture before granting access. The resulting authorization is pushed back to the network device as a VLAN assignment, access list, or security group tag.