Nathan, >From what little understanding I've gained during this ordeal, it should be possible to use two different authentication methods, and in fact to have one fail through to the next using the "Fall-Through" = Yes parameter.
I'm having trouble locating it again this morning, but there was a page, possibly at http://deployingradius.com that discussed using two auth methods for two different NT domains, having one auth to the local Samba server and the other auth to a proxy on an AD server. If you can seperate your users by some characteristic - IP range, Domain/realm, then you can use that to direct to different look-ups. Otherwise I think I would try to use "files" with a fall-through to "NTLM". - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html