On reporting endpoints failing authorization, we may run the report "RADIUS Authentications" and filter on 15039, which is Rejected per authorization profile, as the Failure Reason.
On reporting specific vulnerabilities, if they are posture checks, then we run the report "Posture Assessment by Condition" and filter on the condition names. If they are data collected by application visibility, then we use ISE Context Visibility > Application.