Hi,
I am using server08 Network Policy Server authentication MSCHAPv2, PEAP clients based on security groups in AD. I am also using hte SSO (single sign on) so that the users have access to groups based on there configuration in AD - and i am not running certificates, I plan too, but haven't rolled it out at this stage and everything still works fine.
The certs will ensure the clients are connection to a valid source and that no one can "copy" your authentication server in order to gain credentials from a end user device.