a few limiting facts of using NPS as Radius:
I too was confused by that part of the instructions. We’ve run our own CA for years and my computers have the CA as a Trusted Root without having to push that through Group Policy.
I just confirmed my computers see the most recent Root CA in the Trusted Root Authorities list and it isn’t pushed via a GPO.
Not sure if it’s required for some other scenario- but it isn’t required in our setup.