Not sure if this will apply to wireless but this is how I did it for wired devices. On my system, ISE adds the guest users mac address to the appropriate endpoint identity group based on the Guest Type profile. I setup a re-authentication timer on ...
Yes this can be done and it sounds like you have ACS configured correctly. However, I am not sure if all show commands will be available without entering enable mode. For example, show interfaces is not available until after you enter enable mode.W...