As per this previous post, I can fix this error by matching authorization policy per ISE server . What dictionary attribute do i need to use to make this happen. And yes it works if I use the primary node only in domain but for failover we need both.