The principle cause of all these problems, and what NAC is attempting to solve, is that tying endpoint compliance or admission to one of many types of network use is challenging because you cant force the user to initiate the compliance process before potentially spreading malware. NAC solves this by moving the compliance event to initial network access. Before you can do any other function on the network, the device must be authenticated and its compliance level, or posture, must be validated.