Hi Frank,
So in NAC you can have a rule in the Rules Engine that contains LDAP User Group criteria (that keys off the username) as well as a list of MAC Addresses (End System Group criteria), so if the user registers on a device that is in that MAC list, the re-uath that occurs after the portal login should result in matching that rule. If you then use the same username/password on a device that is not listed in that End System Group, a second rule below the first one can be matched and setup to do something different (more restrictive policy assignment).
If you are worried out the MAC spoofing then this may not be a valid solution for you, but also keep in mind that NAC would be limited in methods of determining if the host is a domain-joined machine if the underlying Authentication Type is MAC Auth rather than 8021.x.
Regards.
Scott Keene