Hi JKuo and everyone,
Reading your question, one can keep some further questions about your setup. So YMMV. Here I assume you already have the wireless connections and RADIUS authentication in place and working flawlessly.
I will try to provide some guidelines for what I think maybe fit your scenario.
When anyone talk to me about filtering/mac filtering network access in a Windows network (starting on W2k3 Server) I always tend point the DHCP Callout feature.
This is included in W2k8 R2 Server, but also available to install in a W2K3 Server as well. This works very well!
Basically, after configuring the DHCP server Callout feature described here, you just have to maintain a simple text file in which you put only the ALLOWED/KNOWN mac addresses to your installation.
You can always configure RADIUS filtering in the access point or in the RADIUS policy itself. But if your setup is some king of static, the overhead, may not justify…
Let me know if you need something else.