Authentication is performed first. CoA can happen after profiling though..
Profiling can help mitigate MAc spoofing. Proper VLAN assignment, dACLs will go a lot further in protecting from that specific issue.
I hope you find this information useful, if it was satisfactory for you, please mark the question as Answered.
Please rate post you consider useful.
-James