• Why not just revoke connect on the endpoint from the user? That is, after you in fact determine the privilege is on an end-point and not something else.