You could technically lump them together, and you'd regret it the first time something breaks. Service selection is first match, top down, so one giant service means every condition and every role-mapping rule gets evaluated for every request type, and troubleshooting turns into reading a wall of rules trying to work out which branch a client took.
Separate services keep the blast radius small. Wired and wireless usually want different enforcement anyway, different roles, different VLANs, different posture expectations, and when you split them you can change one without touching the other. Access Tracker also gets far more readable when the service name tells you what happened.
That list you found is a fine baseline. Add MPSK or Onboard services if you use those, and put your most specific services above the general ones since first match wins.
------------------------------
Dustin Burns
Lead Mobility Engineer @Worldcom Exchange, Inc.
ACCX 1271| ACMX 509| ACSP | ACDA | MVP Guru 2022-2023
If my post was useful accept solution and/or give kudos
------------------------------