That is a great question. As I said before I always use LDAP for authorization instead of AD. It offers so much more functionality. As the authentication is pretty straightfoward I can't see any advantage of using AD over LDAP for that. In fact with LDAP I do fun authentication like using email address instead of user.
AD is just so limited. I really can't come up with a good reason to use it, instead of LDAP for both A,A's.....