I think you can grant the support read-only access to the end-systems tab.
So they can find every end-system and can see, what the NAC rules did with them.
Dependend on your authentication method, they can then check, e.g. if the Mac is registered, or the certificate expired, etc.
Read only for the switches wouldn't be a bad idea, too.