The command #show user mac XX might help with the User Role Derivation used.
(Aruba620) #show user mac xx:xx:xx:xx:xx:xx
Name: , IP: 10.10.10.3, MAC: xx:xx:xx:xx:xx:xx, Age: 00:01:13
Role: ssid-authenticated (how: ROLE_DERIVATION_INITIAL_ROLE), ACL: 67/0
Authentication: No, status: not started, method: , protocol: , server:
Role Derivation: ROLE_DERIVATION_INITIAL_ROLE
VLAN Derivation: Default VLAN