This parameter is only applicable in case of a multi-site deployment and represent the names of one or more down-level client ...

This parameter is only applicable in case of a multi-site deployment and represent the names of one or more down-level client security groups that are not already part of the DirectAccess deployment. Specified in DOMAIN\SG_NAME format
These down-level clients can then connect only to the site specified in the EntryPointName param (see description of EntryPointName parameter for more details)