Just spent whole day deploying fresh l2tp-->Mikrotik-->Radius-->WinSRV2019 NPS and searching for solution to this problem.
Our findings indicate, that 2004 when using Windows log-on name and password does pass forward domain name. NPS is actually receiving user.name instead of domain\user.name, thus failing to authenticate user. Only option now to actually store credentials with connection in form domain\username