Machine authentication is sent by the domain device only when the laptop is first booting up, or, when someone logs out of their computer. So for people that lock their computers and do not log out or shut down their computers, their machine authentication status expires in ClearPass after 24 hours, and is no longer machine authenticated. You can extend that parameter in ClearPass to more than 24 hours, but that parameter tracks mac addresses of users who have machine authenticated and can be spoofed to imitate a machine that has already authenticated. In addition, if a user has never authenticated to the machine before, their certificate is not in their user profile, so they cannot connect to the wireless. Those reasons are why it is best to do machine-only authentication, instead of user and machine.
I hope that makes sense.