So just to confirm, the edge switches are Aruba? (Diagram has Ciscos)
You'd want to apply your AAA at the port level. The best way to use this would be with an interface-group
interface-group gigabitethernet "ACCESS-PORT-UNTRUSTED-GROUP-B"
apply-to 0/0/0-0/0/47,1/0/0-1/0/47
poe-profile "POE-PROFILE-B"
aaa-profile "UNTRUSTED-AAA-PROFILE-B"
port-security-profile "PORT-SECURITY-B"
no trusted port
!
What type of authentication are you using? 802.1x or MAC auth?
Have you checked the logs on your RADIUS server?