To accomplish this task, the Cisco ISE administrator must follow these steps: - Create a blocklist identity group. - Add each MAC address of the endpoints that must be restricted from accessing the network to the blocklist identity group. - Create a policy that denies access to the blocklist identity group. - Apply the policy to the network access devices.