Hi,
By "on-hold" you mean you go to your CA and revoke the certificate with "hold" reason? If so, the certificate is still revoked by the CA and published in CRL or advertised via OCSP, the difference is that you can unrevoke it at a later point in time. What happens, is that unless you delete the certificate from the users's store, and it is still valid, it will still be used by his 802.1x profile and presented to ISE. If you have ISE configured to download the CRL or use OCSP, it will see the certificate is revoked and disallow access. ISE doesn't care about the reason of the revocation.
Never tested this exact setup, with "hold" reason, but this is the way it should work.
Regards,
Cristian Matei.