Just to give an update and share a little piece of interesting info:
I was able to setup the system using the provided docs for static assignment, but improving upon it by not actually doing static IP assignment. Using the EAP ID, it is possible to distinguish users in the connection settings. Then, each user can get a pool depending on his permissions, e.g. i now have one pool for "office-workers" and one pool for admins. Depending on that pool, firewall aliases and rules can be generated to accomodate the permissions. Problem solved. No need for each user having its own pool (as long as there are distinguishable groups regarding the permissions).
I was able to setup the system using the provided docs for static assignment, but improving upon it by not actually doing static IP assignment. Using the EAP ID, it is possible to distinguish users in the connection settings. Then, each user can get a pool depending on his permissions, e.g. i now have one pool for "office-workers" and one pool for admins. Depending on that pool, firewall aliases and rules can be generated to accomodate the permissions. Problem solved. No need for each user having its own pool (as long as there are distinguishable groups regarding the permissions).