Here a example if you want to create a explicit rule for NOT in AD group X.
A user with..
- authentication 802.1X PEAP
- NOT in AD group Team (checkmark invert on the right)
- end system group WLAN_Team
- Location Zone Home & SSID Secure Access
will get a Deny Access Rule
So you set the "invert" to reverse the rule = NOT in this AD group
![71e2aaaf60c349598171f40b80f1d055_RackMultipart20160616-58618-fu1ixo-NAC_rule_invert_inline.png 71e2aaaf60c349598171f40b80f1d055_RackMultipart20160616-58618-fu1ixo-NAC_rule_invert_inline.png](/t5/image/serverpage/image-id/5603i75B0464DC1B4265D/image-size/large?v=v2&px=999)