Linux Weekly News just pointed people at an article Microsoft published on Authenticating Linux Clients with Active Directory: http://technet.microsoft.com/en-au/magazine/dd228986.aspx
Intentionally or not, it's a bit slanted to make Linux look like a burdon. Don't let it scare you. The author clearly has some questionable admin skills, but the explanations of how auth works, how it evolved, and how to configure it is worth a read, and will probably solve your problem. I would strongly advise going the Kerberos+LDAP approach because it will make the final switch a lot easier.