Thanks Charlie,
Per your assistant, I removed vlan 10 and all equipmetns such as AD, DHCP and even IAP have vlan "100" ip addresses.
But device mac addresses don't flow to the AD so the authenticaiton fails.
I can see mac address is registered on switch IAP 1/1port though.
I am wondering how devices can come inside vlan 100 on IAP without having ip address. It should have been broadcasted on vlan 100.
Is there any added configuration needed?
device --------> IAP ----v100----1/1Switch1/2----v100----AD.
Regards
Simon