Just create a rule and set the "Location Group" and "Time Group" and choose a profile that either reject authentication or put the client in a VLAN that is not forwarded.
Make sure the rule is used before the rule that allows authentication (rule order).
![3b6ad80d0d9447a2b25323b386200cb8_RackMultipart20160802-124020-lzllo2-NAC_rule_invert_inline.png 3b6ad80d0d9447a2b25323b386200cb8_RackMultipart20160802-124020-lzllo2-NAC_rule_invert_inline.png](/t5/image/serverpage/image-id/4658i8A71A16E7C955B2C/image-size/large?v=v2&px=999)