Do you have access to the run config on one of your edge nodes in your fabric? After assigning the closed auth template DNAC will provision your edge nodes using IBNS service templates. Closed auth provisions order & priority dot1x and then mab. Meaning dot1x goes first and is set to higher priority. However, should this fail it will fallback to mab. There is another template you could use that is lighter on restrictions that is known as Easy Connect. In DNAC if you go to Design->Authentication you can tweak some of the options in the cisco default templates that you assign to your fabric. For example, if you want to use closed authentication but want the order to be mab first you can set it to use mab order first via the gui. Or if you really want to tweak configs you can leverage the template editor to modify the service template deployed from DNAC. I personally have used the template editor to modify things such as dot1x timers, critical auth vlan, and the default voice vlan.
As far as using web auth this should be straightforward. If your edges are configured to support mab just ensure that your authz profiles in ISE are configured to use whichever portal you setup. Something to note is the default webauth_acl that gets deployed from DNAC. I would double check that. Again, note that you can modify this via template editor. HTH!