myUser can connect to VPN otherUser can't. 
 
I copied both accounts and created two new accounts. 
 
vpntest copied from otherUser
vpntest2 copied from myUser
Both these accounts have the same password and that password is in compliance with domain policy. 
 
I removed all AD security groups except the one needed for Merkai authentication as defined in the NPS policy, and the Domain Users group. 
 
Given the same computer, using iPhone hotspot (off corp network), vpntest cannot connect (691 error) to VPN vpntest2 can connect to VPN. 
 
Even newly created users are able to access the VPN. It just seems to be with specific users who have been with the company for a very long time. Even their usernames are different naming convention. Is there an attribute some where that maybe acting as an alias for another attribute? 
 
I'm just trying to think outside the box on this one. Very strange.