HA !
So that is exactly what I was referencing in my first response lol
So basically that group policy you have on the access control settings for that SSID is going to have false positives as you've clearly seen.
I have to deal with this myself, where it thinks that a MacBook Pro is an iPhone and it blocks it. I probably get a client a day for this type of thing.
Two solutions:
1. remove that feature
2. use EAP-TLS with certificate/machine based authentication and then remove that feature