Hi @SAM-Al
It is recommended to have a dedicated VLAN for management traffic, although not always required, per our KB article for Understanding and Configuring Management VLANs.
In your case, I would recommend configuring your aggregation switches' management interfaces in the transit VLAN (so that they can still function if anything happens downstream), and then creating a management VLAN on the aggregation switches for the remaining downstream equipment (access switches, APs, etc).
As long as routing is configuring properly, you shouldn't have an issue with on-premise or cloud based RADIUS server.
Cheers,
-Alex
If this was helpful, click the Kudos button below.
Please mark it as a solution if solved your issue so others can benefit from it 🙂