IKEv2 with RADIUS / NPS and AD CS Certificates

Hello Hello,

I’m setting up an IKEv2 Always On VPN with Windows 10/11 clients authenticating against Windows NPS (RADIUS) on a domain network. I searched alot of posts here and there is there any best-practice to use or to follow, as a Mikrotik fan its frustrating having more as 80 Mikrotik Devices on my productive network running and such simple things taking alot of time.

Best