Hello,
I don’t think we have a “NAC Notification” for this from the NAC Notification Engine (launched via Bell icon at the top menu area in NAC Manager). However, if NAC Manager generates a log event when a user tries to register another device over the max allowed limit, then it’s possible NetSight can send an alarm using “match text” criteria and NetSight's Alarm and Events Manager.
If you do see the message in the log, you should open a case with GTAC for assistance with configuring Alarms and Events.
Regarding the AD question, NAC will send all LDAP login queries to the AD that you configured in your NAC's LDAP Config. If the AD responds such that credentials do not match, NAC will reflect that with an "invalid username and password" error. I'm not sure what you mean by "a good way to deny certain accounts that are in AD". NAC will send queries to the AD per the User Search Root path in your LDAP Config. If the user is not a member of that path, the AD will Reject user and should also result in a username / password error.
Scott Keene,
Extreme GTAC