Before assuming it's a bug, worth proving whether the client hitting the portal is the same MAC that got cached. Randomization is the usual suspect and it isn't ruled out by having worked on Classic, since Windows and iOS both rotate the per-network address on a forget and rejoin, and the two platforms don't necessarily key the cached endpoint the same way.
After a successful portal login, check the endpoint actually exists in Central NAC and note the MAC. Then when someone gets re-prompted, compare the MAC in the client list against that entry. If they differ you have your answer and the fix is client side, disabling private addresses for that SSID. If they match, then it's the caching itself and worth a TAC case with both records.
Also check where your 180 day limit is applied. The profile value and the role can disagree, and the shorter one wins.
------------------------------
Dustin Burns
@Worldcom Exchange, Inc.
If my post was useful accept solution and/or give kudos
------------------------------