Both of those MACs are randomized. 42:E0:36 and the 52:76:8D one from your earlier thread are locally administered, second bit set in the first octet, so you're not looking for an unknown rogue device. You're looking at a device using a private address, almost certainly a phone or a personal machine that has the user's credentials saved.
With PEAP-MSCHAPv2 that's the classic lockout pattern: the user changes their password, some other device keeps retrying the old one every minute, and AD locks the account. Resetting credentials and rebuilding the laptop profile never fixes it because the laptop was never the culprit.
Search the endpoints repository for that MAC and see what ClearPass profiled it as, then check the AD lockout events for the caller MAC and the source NAS. That gets you the AP and radio it's on, and you can walk it down. Long term this is the argument for moving that SSID to EAP-TLS, since a certificate can't be stashed on somebody's phone the way a password can.
------------------------------
Dustin Burns
@Worldcom Exchange, Inc.
If my post was useful accept solution and/or give kudos
------------------------------