The global command:
aaa server radius dynamic-author
...enables the RADIUS server (e.g., ACS, ISE etc.) to send Change of Authorization (CoA) commands to the switch telling it to vary parameters for the port. Those include the VLAN, ACL (or dACL), port disable etc.
See more details at these locations (among others):
http://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-services/whitepaper_C11-731907.html
http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/15-sy/sec-usr-8021x-15-sy-book/sec-rad-coa.html