Should everyone have the same access within the organization?
Should users have the same access no matter what device they do use?
Building your firewall rules based on both a segmented network and identity will give you great flexibility and somewhat of automation.
This allow you to limit access for users based on what type of device they are using and what ad groups they belongs to.
ie: Corperate device + AD group = Admin access
BYOD + AD group = User acess.
But you dont loose any mobility, users will be able to move between offices, wifi, vpn and keep there access.