I know its old, but still relevant! I've gone through and double checked the certificate side of things and can't seem to fault it. In my test environment I'm running all components on the one server (RRAS, NPS, CA, DHCP, DNS and AD).
Did anyone actually get this working? I've followed this guide, the microsoft guide and another here: https://4sysops.com/archives/active-directory-group-policy-and-certificates-for-always-on-vpn/ but can't seem to get things to work. I keep getting the same IKE error 13806.