Haven't tried, but under Onguard Settings - Policy Manager Zones, you can override/force the IP/FQDN that the OnGuard agent will connect to. You may set it to an FQDN that's only internally resolvable. Or you can add only your corporate IP space in the default zone, where it may be (again untested) that the client will only report if it's in one of those IP subnets.
Doesn't help if people at home or on the road use an IP that overlaps with your corporate range. Also may not stop the client from enforcing/performing checks.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------