In my opinion you should lock down MAC authenticated clients as much as possible. Phones will only have access to the PBX, IP Cameras just to the recording systems, etc. If you evaluate the risk of someone spoofing the MAC address of an IP Phone and get to the PBX, you may accept that instead of jumping loops to configure 802.1X on the phones. Providing full network access to devices based on just MAC Auth should really be avoided.
And yes, you can do all kinds of smart things, like if you manually register devices in the Endpoint database, register there the Device Name (profiling), and during rolemapping/enforcement check if the device is still classified as the device that you authorized. Or purely work with profiling, assign as restricted as possible roles, and use the Profiler tab to trigger a CoA as soon as you get a conflicting/updated fingerprint.
It also may be good to understand the observations of the pentesters, and what would be good enough for them, and also check with the security policy what is needed to comply with that.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------