Please find attached an MS PowerPoint describing step by step how to automatically provision RADIUS users to your CA PAM.
For this the “Standard RADIUS IETF Attribute 25 (Class)” in the RADIUS Server is utilised which holds the name of the user group defined in the RADIUS server.
Members of this group will be automatically provisioned in CA PAM upon first time login.
Demonstration is performed on an MS RADIUS server hosted on a Windows 2012 R2 Domain Controller - but should work the same on any other RADIUS server supporting this feature.
I hope you find this helpful.