We do this by the following way. We activate MAC Auth at all ports via Policy Manager and create a Rule "Allow All". In NAC we create a Profile with Response of this Policy "Allow All". Then we create a rule and put in this Profile. So you can see all Clients behind you Switch Ports and in the first step they will be allowed to connect. In other steps you can create End-System Groups and other criteria and do an authentication.