So I found this page, which indicates that the policy attribute 'group-lock' is used to limit a vpn group-policy so that valid users can only login to groups to which the radius server says they ...