Hi, I don't have an example to hand, but you are able to do exactly what you have asked. You can create AuthZ rules to match specifically on the authentication method used. I assume when you say domain computer you mean PEAP/MSCHAPv2, that is the most common authentication method.
For MSCHAPv2 you can create a AuthZ rule to match on "NetworkAccess : EAPAuthentication Equals EAP-MSCHAPv2".
For certificates you'd create another rule and use the condition "NetworkAccess : EAPAuthentication Equals EAP-TLS".
ISE will go through the rules top down until a match is found, once matched it will not process the rest. So in this example if you've deployed certificates and the client supplicant is configured to use EAP-TLS it will not match on the EAP-MSCHAPv2 rule and progress to the next, hopefully matching the EAP-TLS rule.
You can combine other conditions, such as AD domain group membership and use MSCHAPv2 AND Domain Computers etc.
HTH