ClearPass can be configured for TACACS with Cisco Switches. ClearPass can work with multiple user stores, including the local user database within ClearPass itself or an external user store such as Active Directory. Within the policy for your TACACS service you will be able to determine who has enable access or not.
It would be possible to allow IT/Network Administrators to access switches using their domain credentials for example so they do not have to remember alternate credentials. This also helps with auditing who has accessed and changed switch configuration.
You may find some value in this thread:
https://community.arubanetworks.com/community-home/digestviewer/viewthread?MID=13506Also this ASE configuration guidance:
https://ase.arubanetworks.com/solutions/id/80There is also a
YouTube video for Radius and Tacacs on Comware 5 with Aruba ClearPass. While the switch OS is different you may find the instructional video useful.