I implemented this for couple customers, but it can get little tricky. Say, for example, you have 500 people in your company and you want only 50 of them using Radius for MFA. Well, its not as easy as referencing that group in AD for radius auth, what we had to do is create local vpn users in dashboard and set their auth to Radius and then update the proper vpn/access role groups to allow them access. This is not sadly scalable for lots of users, but it does work. Message me privately if you want to do remote, Im happy to show you.
Cheers!
A.