I found the missing link!
On the NPS server, I had to set the following registry entry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AzureMf
Create the following String/Value pair:
Name: OVERRIDE_NUMBER_MATCHING_WITH_OTP
Value = FALSE
Then I had to restart the Network Policy Service and BINGO! I got the approve sign-in notification on my phone when I tested the RADIUS logon. Because I had number matching turned on in my tenant, the extension was falling back to TOTP which obviously won't work with MSCHAPv2.
See this link:
https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-mfa-number-match#nps-extension