I have the same issue at a few of our SD-WAN sites with Radius and EAP-TLS certs. My solution was to use the Meraki Cloud Radius Proxy for these sites - the request goes out directly across the internet (Not over SDWan where there is added VPN packet overhead) to the radius proxy and then onward into datacentre where the request is accepted and returned back to the cloud radius and onto the WAN site.
Note: The meraki radius test feature (where there is no added user certs packet overhead) worked fine at these sites where it was only using username/pw authentication
I found changing MTU size on NPS radius made no difference - you have little or no control on the MTU size across your ISP links etc
Some pings showing packet fragmentation and comparing against working sites may help you check if MTU is your issue