Whats it intercepting? Apples detection sends a HTTP/HTTPS request to captive.apple.com. If it fails, it assumes a captive portal. Theres also a DHCP option apple supports.
But even after detection, theres redirection.
Have a look at WAP Vendor options.
Heres Powerlynx explicitly requests disabling HTTPS before auth on Cambium in their user setup guide.
https://docs.powerlynx.app/networking/cambium.html
"Redirect HTTP-only - On"
This guarantees that, upon redirection, you are presented with a HTTP login page for the captive portal. And then any subsequent redirections, also have to be HTTP.
Heres Start Hotspot
https://go.starthotspot.com/help/cambium/
"Redirect: Tick HTTP-only"
Cambium supports more modern methods, but captive portal vendors are not going to shift before letting their customers fall on their face.
(Also, cambiums guest access whitelist is based on DNS and breaks with DNS over HTTPS/TLS)