If you know the mac address then follow below steps,
1) Create the policy
wm3400-34710C8(config)#association-acl-policy
2) Deny or allow the specific mac address

deny 11-22-33-44-56-01 11-22-33-44-56-01 precedence 160
permit 11-22-33-44-66-01 11-22-33-44-66-FF precedence 170
3) Apply the policy to specific vlan or WLAN.