So the following Net login rules apply, for the products below.

If you create a end systems group within NAC for the MAC address or some other identifier for the AP's, then you can then add a specific egress policy as well. If that egress policy is just a VLAN for one physical node, than it can be modified accordingly.

So in the above, the policy can have a VLAN assigned discretely, or if multiple VLAN egress assignments need to be done (based on only one mac being added to the port), than a filter-id assignment would need to be provided here, and matched up with Policy Manager or policy to modify the egress tab with that software.

This assumes the X440-G2 is the product, and running fairly recent firmware with it as well.
So this is not a solution discussed above, merely guidance on the discussion.