when you create the Auth source for your AD, you need an AD user account with read-only permission. So you can change the permission for your clearpass service account from Full. to read-only.
------------------------------
If my post was useful accept solution and/or give kudos.
Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
------------------------------