Hi,
Network Policy Server (NPS) provides authentication, authorization, and accounting services for network access servers, such as IEEE 802.1X authenticating switches and wireless
access points, virtual private network (VPN) servers, dial-up servers, and computers running Windows Server 2008 with Terminal Services Gateway (TS Gateway).
As you said, there are only a few users; you can deploy your VPN without NPS.
But if the VPN is built in domain, youd better configure a NPS to protect your intranet.
More information about NPS:
Network Policy Server (NPS)
http://technet.microsoft.com/en-us/library/cc735378(v=WS.10).aspx