Author Comment: In 10.10.01, the following statement was "To configure a AAA Network associated to a Default Auth Role accept policy." No indication why this was modified. Flagging as update for 10.13.01 review.
To create a AAA network associated to a Pass-thru External RADIUS Accept Policy. Take the following steps:
On ExtremeCloud IQ Controller :
Use the IP address of the Access Control Engine—that is, the Network Access Control (NAC) server—as the primary RADIUS server.

Note
To find the Shared Secret of the Access Control Engine, log in to ExtremeCloud IQ Site Engine and go to:Control > Access Control > Configuration > Global and Engine Settings > Engine Settings.

Note
Both B@AP and B@AC are supported for NAC.
On ExtremeCloud IQ Site Engine:
On ExtremeCloud IQ Controller:
Associate clients to the SSID of the Network, when prompted for the username and password, use the username and password created with the New User. The external NAC server matches the rule you created under New Rule and upon successful authentication sends an Access-Accept and a Filter-ID Enterprise User. The ExtremeCloud IQ Controller Access Control engine applies the Enterprise User Role instead of the Default Auth Role that was configured under Network Settings.
Author Comment: In 10.10.01, the preceding paragraph stated "The ExtremeCloud IQ Controller Access Control engine ignores the Filter-ID and applies the Default Auth Role that was configured under Network Settings." The following Note was added too. No indication as to why this was modified. Flagging as update for 10.13.01 review.

Note
The Enterprise User role must exist on ExtremeCloud IQ Controller and must be assigned to the same device group as the client in order to be applied.