In the event that a user loses an endpoint
that provides GlobalProtect access to your network, that endpoint
is stolen, or a user leaves your organization, you can block the
endpoint from gaining access to the network by placing the endpoint
in a block list.
A block list is local to a logical network
location (vsys, 1 for example) and can contain a maximum of 1,000
endpoints per location. Therefore, you can create separate block
lists for each location hosting a GlobalProtect deployment.