Not sure, what you want to achieve.
You can sync users and groups based on LDAP filters into AEM. Normally one would maintain the group memberships and authentication stuff in the AD, and just use the groups in AEM, probably as basis for ACLs. That's the standard approach when you want to use a LDAP sync.
Jörg