Your comments

Without digging to deap these are the 2 options that jump out at me as something we'd like to control at group level. Idealy we'd be able to to control all options that affect how the agent works/allows connections or responds to them from the group level.

Lock machines on disconnect: we have servers and workstations that are unattended no one uses them and we'd like to be able to lock these on disconnect.
Ask for Consent. - We have workstations and servers which are unattended and we'd like to be able to connect to these without consent but all users machines we want to default/continue to ask for consen.