It looks like I get an error message when attempting to use a wildcard in a domain netdestination (e.g. *.google.com) in the ClearPass standard downloadable user role enforcement profile configuration (see attached). However, if I configured the same netdestination on the controller, it would be allowed.
Would this work when using the advanced mode or this expected behavior and a limitation of DURs?