Regarding the error, I found the fix to be a combination using the with_ntdomain_hack = yes, and the modification to the hints file. In order to allow everyone wireless access, while only granting members of the "VPN" group VPN access, I added the following to /etc/raddb/users:
DEFAULT Group == "VPN", Auth-Type = LDAP
Fall-Through = NoDEFAULT Auth-Type = EAP
- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

