Thank you for confirming. Yes, it is possible to configure the role such that only corporate machines, any OS, can login. I would recommend checking with your admin (or if you are the admin, run a policy trace on your username & see what happens between the two scenarios)
-Starting with Mac OS X 10.9 and above, Network Connect is no longer supported -Also can you check if WSAM is enabled under the User Role that is been obtained for the MAC users -- Go the User role that the MAC user is obtaining -- Under General -- Check if WSAM feature is enabled. If so disable the WSAM feature and check if you are able to login.
Note: If you are getting mutiple roles -- Make sure the WSAM is disabled on all the roles that they are obtaining and check if it helps