Just create a rule and set the "Location Group" and "Time Group" and choose a profile that either reject authentication or put the client in a VLAN that is not forwarded.
Make sure the rule is used before the rule that allows authentication (rule order).