Hi
As mentioned the static host list will for sure work, but the static hosts lists are mostly left in ClearPass due to backward compatibility. The user interface for the static host list is quite user unfriendly, in my opinion. The entries are added in cronological order and it's not possible to search in the list.
Why not have both EAP-PEAP and EAP-TLS in the same service? Eventually you need to modify the AD search query to search for both sAmAccountName and UPN, but if the only difference is the authentication method I would recommend having only one service.
The reason why you can't utilize an AD attribute is that the AD information is read after the actual authentication has taken place. You can also add a custom attribute to the Endpoints repository if you would like to have two services. Endpoints repository is searchable but depending on your administrative delegation of rights the static host list can be a better option if you need to delegate the right to add MAC addresses to a person who is not familiar with ClearPass and you would like to limit the damage they can do.
------------------------------
Best Regards
Jonas Hammarbäck
MVP 2023, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACDP , ACEP, ACSA
Aranya AB
If you find my answer useful, consider giving kudos and/or mark as solution
------------------------------