Hi Marcus,
you configure authentication in NAC and the switch normally (without policy or VLAN assignment), but then you add the port configuration to not actually require authentication:
configure netlogin ports PORTS authentication mode optional
Note: This is supported for OnePolicy only (i.e., with enable policy as part of the configuration).
I would expect that this can be achieved using the XMC ("NAC") web frontend as well.
If authentication is successful and sends policy and / or VLAN information, those will be used. Thus you should configure NAC to not send any policy or VLAN assignment to those switches where you only need the visibility features of NAC.
Please test this before actually using it in production!
Thanks,
Erik