What mode do you use on the B5 for the authentication? I would recommend you to set "set policy maptable responce booth" that the switch accept all whats coming in, Policy's AND RFC3580 Vlan auth. Please check also the authentication status on the B5 if the client did not get a ip address with "show multiauth session port ge.x.y"
Did you set the clients ports to edge = true?
Do you have static policies on the user ports? If yes, please do NOT assign policies statically, assign it with the authentication, works better 😉
For security features I would recommend you to use a "blackhole vlan" as PVID on the user ports (blackhole means a vlan you NOT transmit between your switches), some clients always try to get there old IP Adresse, thats an NIC driver mistake, best fix is therefor this blackhole vlan.
But this only use for Windows's PC's. If you have "silent devices" that not speaks out traffic like door control panels with Ethernet interface you should assign the Vlan that the authenticated client will get after a successfull authentication. This makes it sure that the silent device will get the request for his mac address and he can answer, and with THAT answer you authenticate it again.