Because you are using NPS you have limited options, but you do have one. You'll need to setup two Radius server definitions and server groups. They will both point to the same NPS server and use the same shared secret. However, for each server definition, define a unique "NAS ID", for example Staff-SSID and Student-SSID. Then setup your AAA profiles to use the respective server group. Last, setup two NPS policies, one for Student authentication and one for Staff authentication and the appropriate returned attributes. In the conditions, make sure you have the NAS Identifier in there to differentiate the requests as wel as AD group memberships.
For example:
aaa authentication-server radius "nps-staff"
nas-identifier "Staff-SSID"
aaa authentication-server radius "nps-student"
nas-identifier "Student-SSID"
(ClearPass could use the Aruba-ESSID-Name atribute).