Even with Edge-safeguard enabled? Below is a sample config of what I've used.
create vlan "STPVlan"configure vlan STPVlan tag 1111
configure vlan STPVlan add ports all tagged
configure mstp region STPVlan
configure stpd s0 delete vlan default port...
How about adding a tagged vlan to all your end system ports, such as STP_VLAN? You can setup that one vlan to do spanning tree and then you can leave it alone, and add and delete other vlans off of the port, without affecting your STP config.
In Policy Manager with XOS switches, I've had to put in a bogus number in the field where mac auth password is at. Click on the network device in PM, go to Auth tab, and under Mac Auth settings, check the box for password and insert a password there...