You need to enable TACACS+ / RADIUS device administration when you use Aruba Clearpass and Azure AD.
Since Azure AD does not support LDAP or MSCHAPv2, so ClearPass cannot query Azure AD directly. You must integrate in one of these ways:
1. Entra ID (Azure AD) + SAML 2.0 for ClearPass Admin Login Only (NOT for TACACS+). This works only for logging into the ClearPass web GUI, not for managing switches.
TACACS+ cannot use SAML, so this does NOT solve device management.
2. Use ClearPass Azure AD Secure Client / OAuth 2.0 / Graph API (REQUIRED for TACACS+ or RADIUS device admin). This is the correct method for switch management.
I guess technical details on how to do such configs, you can find online. If not, we can check if we can help.
------------------------------
Shpat | ACEP | ACMP | ACCP | ACDP
Just an Aruba enthusiast and contributor by cases
If you find my comment helpful, KUDOS are appreciated.
------------------------------