Okay, first up: Everyone is putting their account name, not domain.local\accountName, right? RADIUS just needs the account name. Second, the clients are testing from outside the work network? Hotspots can be used to test but they must ensure that the hotspot is not connected to the local wireless. Third, Windows 10? I've got scripts in my signature that setup a Win10 saved VPN connection better. There's comments that describe what each bit does. One script for large deployments; the other for help desks that handle multiple clients.
... View more