In my lab the MX is concentrator mode. So not a interface dropdown, but rather an open field to type a non default/native VLAN ID. But I don't think the behavior would be any different.
In my usual setup I have the tunneled SSID drop clients into VLAN 600 (a DMZ subnet).
In my testing this morning I added VLAN 90 to the switchport connected to my MX. Then for the IPSK and RADIUS tests I set VLAN 90 as the VLAN tag (IPSK) /Tunnel-Private-Group-ID attribute (RADIUS). For the RADIUS config you of course need to enable the toggle for RADIUS override for the VLAN tagging to work.