I'm not sure about using a range of internal IP addresses, that could get messy. The certificate-based authentication with the Windows Device Trust agent sounds cleaner to me.
Option B seems like the way to go here. The Windows Cloud Agent and CyberArk Identity Connector with Integrated Windows Authentication should do the trick.
Roslyn
9 days agoGlenna
14 days agoDierdre
2 days agoFelicitas
16 days agoEllsworth
18 days agoDyan
23 days ago