Im curious how they get a work around for this. The way that the system is designed to work (EAP-MSCAPv2 or the like), the username and password must be in the EAP packet for the flow to continue and since no user is logged in, we cannot process usernames and password leading to a dead stop in the process flow. Additionally im not sure if ISE allows for conditional policy elements that continue after validation, currently the policy set stops on first match, not continue on first match.