Dave,
You're trying to actually log into the ZD/SZ, yes? If you have it all configured and you're getting the proper accept message within your NPS logs, are logging in with your full AD address (email basically)? We log in to a vSZ via our AD/NPS/RADIUS but the vSZ only support PAP/CHAP and we had to make some adjustments to our NPS policy and even then we still have to use the full account name (@).