NAC can enforce policy through several mechanisms:
VLAN assignment. Compliant devices get the production VLAN. Non-compliant devices land on a quarantine VLAN with limited access.
Access control lists. The NAC system pushes ACLs to network devices, restricting what non-compliant endpoints can reach.
Inline enforcement. Traffic flows through the NAC appliance, which blocks or allows based on endpoint status.
X integration. NAC and RADIUS work together. RADIUS authorization attributes assign VLANs or ACLs based on posture assessment results.