Hello ncustod,
In this case, what you could do is, have a backup server configured for the AD in the Authsources. two things might happen if the primary authsource (AD) goes down.
1. If Clearpass is not able to establish a TCP session, with the AD. It will realise that the AD is down and will move on to the backup AD right away and the auth will work.
2. If Clearpass is able to establish the TCP session. in this case, you could configure the Authentication server timeout to 2 secs, in the Authentication sources on Clearpass. default is 10 seconds, it will timeout at 2 seconds and perform auth with the backup server.
You cannot use, Local creds on Clearpass, automatically upon the failure. the only automatic redundancy is mentioned as above. Alternatively, if you are ok with manaul intervention, if the users are failing AD auth, you could create the local user accounts for them on the devices directly or on the clearpass, Users can use local creds on the devices to login, when AD auth for them doesnt work. For the users created on the Clearpass you will need to do some configuration change on the clearpass.