Dear Avery Brennen,
Based on the information provided, it’s clear that the trust relationship is correctly configured with Selective Authentication, and both NPS servers are registered and forwarding requests as expected. The error message—“Authentication failed due to a user credentials mismatch”—suggests that while the RADIUS request is reaching Domain A’s NPS, the credentials are not being validated successfully.
Given that multiple username formats have been tested and local-domain logins are successful, we recommend verifying the following additional areas:
Ensure that Domain B’s NPS server has been explicitly granted the “Allowed to authenticate” permission on the Domain A user accounts or groups, as required under Selective Authentication.
Confirm that the authentication protocol (PAP) is supported and permitted for the user accounts in Domain A, especially if any conditional access or password policies are in place.
Review the Connection Request Policy and Network Policy configurations on both NPS servers to ensure they do not inadvertently filter or reject requests based on domain or authentication type.
We also suggest enabling detailed logging on both NPS servers and reviewing the Security Event Logs for any Kerberos or NTLM-related failures that may provide further insight.
If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.
Best regards,
Harry Phan