I'm trying to figure out how to provide unique tunnel policies based on Active Directory groups. I have ASA pointing AnyConnect VPN users to ISE for Radius. In Radius, Authentication is working fine. And I have a Authorization Policy that allows users of a AD group to gain access, but I need to have 2 or moth authorization policies that allow access based on groups. Those Authorizations would then be assigned to unique tunnel policies on the ASA.