We've been using the Cato client with Always On and Connect on Boot for a while now.
We enabled Pre Login with our DCs as allowed destinations.
We have a device certificate and signing certificate already as we use these as part of our device posture checks.
The registry was updated automatically on all connected devices once Pre Login was enabled in the CMA.
After a reboot my login session hung, just sat there at the welcome screen with the spinning dots so disabled Pre Login in the CMA and login worked ok.
I see a number of people are using Pre Login, did you have any issues when you were setting this up ? any ideas where to start troubleshooting ?
It's very difficult to do any testing as once it's enabled in the CMA the registry setting is pushed out to all connected users.
Ideally this would be policy based and could be applied to a test group.