It seems like your windows 7 device missed the root ca and or intermediates in your client trust store. This is needes so your client can trust the server radius certificate your radius server is sending.
I believe that TLS1.0 should be disabled as its considers as not secure.
Also note that EAP-PEAP is not secure, credentials can be easy be stolen. Dont't use it in a production environment. A little bit protection can be set in the client profile where the client should not be allowed to accept new server certificates (lower checkbox)
See also this video by Herman.
Verstuurd vanaf mijn iPhone