If you plan on reusing the pre-configured default Admin Realm then:
1. Define the NPS server as a Radius Auth server under the Auth Server Menu
2. Under Admin Realms Menu select the Admin Users Realm and change the Autentication server to the NPS server instance defined in step1 and save changes.
3. Then go to the role mapping tab and create a new Rule based on User Attribute and select the attribute which the NPS server will send with group membership info.
Note: If you are changing the pre-configured default Admin Realm then its better to have serial console access in case you lock yourself out