If there is no RADIUS request, it is likely the default PMKsa-caching on the APs. You could: Ask Meraki Support if they can disable it. Not sure if that is possible. Reduce the session timeout on the RADIUS-server to limit the amount of time the client could continue with disabled account.
... View more