Hey,
From "these devices only use an object in AD with a certificate name mapping applied to to authenticate it" - I suspect that the iPads have an AD object in order to have the certificate, or you push the certs through an MDM solution !?!?!?!?
Either way, you need to have an AD Object and made that object part of an group, so then you do Machine Identity and based on that AD group you could allow the Internet Access....
For the Radius Accounting, you need to point your WiFi authenticator to send Radius Accounting to the IC (Identity Collector) and that would grab the data from User/Machine Identity and use it.
btw, are you using Identity Collector ? If not, you could try it and you will be able to se User/Machine authentications and use those too...
Ty,