Hello,
I am sharing the attached documents which refer on how to Integrate the ACS 5.x with Windows AD and also how to configure the ACS 5.x in order to handle PEAP Authentication Requests. Those documents were created for my own reference but had become very useful when a "step-by-step" guide is needed in regards to PEAP authentication on ACS 5.x.
As per the "fallback" configuration in order to authenticate against MS NPS if ACS is not available that should be performed on the AAA client (AP, WLC, WCS) as the fallback occurs at the AAA client side. If the ACS fails to respond or the requests times out then the AAA client triggers the fallback and contacts the next configured server for authenticate.
NOTE: As ACS 5.x is quite a new version there are not that many configuration examples on Cisco.com as there used to be for ACS 4.x.
Hope the attached documents point you into the right direction.
Regards.