That is correct. it requires active session in ISE to send CoA.
Have you tried the Auth-VLAN (Guest-VLAN) solution for 3rdparty NADs?
Please make sure the 'Send SNMP COA separate request' option is enabled in imported NAD profile.
and make sure you have SNMP community with RW.
'snmp-server community ciscorw RW'
'ciscorw' is community string
if that doesn'...
Please follow these steps:
1. Extract the zip file
2.Import the xml file into ISE under "Administration >Network Resources >Network Device Profiles"
3. Create network device and select this NAD profile in network device page.