OK, lates test results.
I have a local db account that is active, an Android device connects using the account. I then send the command "local-userdb modify username <name> mode disable", then I send "stm add-blacklist-client <mac>", then 10 seconds later I remove the blacklist with "stm remove-blacklist-client <mac>". The account is still disabled, but the device rejoins the network.
What I'm attempting to do here is to disable an account and have all devices associated with that account kick-off the network. But, if I re-enable the account I don't want to have to attempt to find and remove the device from the black list, as I may not know the device then. I am sending the commands to the controller using an SSH session. Is there a better way of doin this?