Not sure what you configured today for mschapv2 on your switch, and normally for aaa port-access you configure the EAP method (PEAP-MSCHAPv2 or EAP-TLS or TEAP) ion your RADIUS server (probably NPS in your case), and on the client and on the RADIUS server, not on the switch.
It's strongly advised to move away from legacy mschapv2 as the protocol has known security weaknesses (for years already) and EAP-TLS or other EAP methods with client certificates are the most logical direction. You don't need ClearPass for EAP-TLS, you should be able to configure that with NPS as well (I know it's possible, but don't ask me how to do it). With ClearPass it's just much easier to set up and more important to troubleshoot if you have issues.
As this is a quite radical design decision, it may be better to work with your Aruba partner, or someone familiar with this subject and your environment as it's important to get this designed properly. The switch models are less important as it's all standards based.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------