You'll need to add an allow policy to the captive portal role.
Add an allow to the Alias for the DNS name. Make sure your controllers have a valid DNS server defined.
netdestination cloud-login_microsoftonline
name login.microsoftonline.com
name *.aadcdn.microsoftonline-p.com
!
Ref: ClearPass Clouds Services GitHub
https://github.com/aruba/clearpass-cloud-service-whitelists/blob/master/cloud-login/cloud-login_azure-active-directory.md