I'm investigating, but you should be able to use a UPM profile specified in a VSA associated with the account passed from the radius server through the NAC as a proxy.
You would have to configure the UPM user-authenticate event on every port where you want DHCP to be enabled. Here is an
article on how to use UPM for authenticating clients.
I'm investigating if NAC as a proxy somehow interferes with the VSA being passed from the radius server, but I do not believe it does. I assume you are using NAC as a proxy to a radius server, right?