hi,
have you set up the AD like this : https://thesolving.com/server-room/configure-radius-server-windows-authenticate-cisco-vpn-users/
And make sure you specify the right container for users:
AD Domain name : example.local
Primary Server: Your Ad IP , port 389
User container Path : cn=users,dc=exampledomain,dc=local
Than Make sure in AD that all allowed user are part of the VpnAuthorizedUsers Group. ( described at first step)