I think I may have found the answer experimenting on another thread. If you don’t want the AP to issue an IP address if the mac returns a “Access-Reject” from RADIUS, you can set the DHCP server for the AP to use RADIUS for authentication. If the RADIUS server returns “Access-Reject” for the mac, the mac is not issued an IP. Would that help?