Z,
We are not monitoring endpoints. The wireless networks are essentially treated as "Guest Networks". UDT logs all of the MAC Addresses that are seen on the wireless and tracks which APs they have been seen on.
Perhaps the approach is to look at each MAC address, alert if it has been both associated with an SSID, and seen on a port?
-ct