I can't see any reason why that wouldn't work and long as it is a straight up authentication with no additional authorization. After all, ISE is just a RADIUS server. You might want to starting trying using PEAP first and see how that works before getting into EAP-TLS.