In case this will help any one else, I've figured this out....
Here is a link on how to find the logs for NPS...
https://social.technet.microsoft.com/Forums/windows/en-US/45aa3000-c32b-483b-8d6e-565b56b163fc/how-to-check-the-nps-logs-in-the-event-viewer?forum=winserverNAP
Basically there are text file logs in c:\Windows\System32\LogFiles\In* , or you can check in Event Viewer under Diagnostics -> Event Viewer -> Custom Views -> Server Roles -> Network Policy.
In my case, the problem users were set to "Deny Access" under the "Dial In" tab of the user properties in AD Users & Computers. Setting to Allow Access fixed it up.
If you don't see the "Dial In" tab, this may be of help :
https://support.microsoft.com/en-ca/help/975448/the-dial-in-tab-is-not-available-in-the-active-directory-users-and-com
For me, I had to be on the server to get that tab, not accessing Active Directory Users and Computers on another PC.
Hope this will help someone else.
Thanks, Derelict for pointing me in the right direction!