Maybe I‘m completely missing something here, but RADIUS as the Protocol Sporen between NAD and authentication Server itself doesn‘t have any relation to TLS.
Are your referring to specific authentification methods like EAP-TLS? Or are you using RADIUS DTLS between MR and your RADIUS server (if so, I didn‘t even know that this is supported on MR).
EDIT: I‘ve finally taken a look at the link provided. This is then purely related to your authentication method spoken between your endpoint and your „RADIUS server“. Both agree on specific parameters for authentication, but a network device posing as a „proxy“ between them doesn‘t have anything to do with that. It simply „translates“ Layer 2-based EAP to Layer 3-based RADIUS.
Meraki support is completely right by saying that this is outside the scope of their support. Sorry to say that, but ditching NPS and switching to a real RADIUS server has helped a lot of our customers to have a decent nights‘ sleep. 😉