Configure a RADIUS server for Wi Fi authentication
Everything You Need to Know About PEAP Security
Configure 802.1X Authentication with PEAP, ISE 2.1 and WLC 8.3
Radius Server for WiFi Authentication with Windows Server
How to Configure RADIUS Server to Secure Wi-Fi Access Domain User Credentials on Windows Server
Secure Wi-Fi with FortiAuthenticator & Active Directory (RADIUS)
Secure Your WiFi with RADIUS: A Step-by-Step Guide
Please note some important facts
(1) NPS server has valid certificate
(2) Same shared secret is being used in Radius server and radius client
(3)`NPS service is running
(4) NPS server is registered in AD.
(5) NPS server is part of RAS and IAS servers group.
(6) User is part of correct group that you defined in your NPS policy.
(7) No communication block in Radius server and radius client
When connecting to a network that is configured to perform PEAP-MS-CHAP v2, PEAP-TLS, or EAP-TLS authentication, by default, Windows wireless clients must also validate a computer certificate that is sent by the RADIUS server. The computer certificate that is sent by the RADIUS server for every authentication session is commonly referred to as a server certificate.
As mentioned previously, you can issue your RADIUS servers their server certificate in one of two ways: from a commercial CA (such as VeriSign, Inc.,), or from a private CA that you deploy on your network. If the RADIUS server sends a computer certificate that was issued by a commercial CA that already has a root certificate installed in the client's Trusted Root Certification Authorities certificate store, then the wireless client can validate the RADIUS server's computer certificate, regardless of whether the wireless client has joined the Active Directory domain. In this case the wireless client can connect to the wireless network, and then you can join the computer to the domain.