This is doable except for assigning different VLANs.
Unfortunately when a device is connected to a captive portal type wireless access , the device is not able to detect the VLAN change and think it still on the original VLAN that was assigned when it landed on the captive portal role.
Best is to keep the same VLAN and then assign different user-roles to determine the type of access the user/device will get.
To do the SSO portion, you will need to configure an enterprise application in Azure to use SAML and define in ClearPass the application that will use SSO as well as the application authorization service.
Edit the SAML signing certificate and create a new certificate and make sure to make it active

Download the certificate (Base64) and upload it to the ClearPass trust list and then map it out as the IdP Signing Certificate in the CPPM SSO config

