that’s odd… if NS is a member of an AD forest, it uses users from AD…
that said, all daemons must search/use ldap against AD
see, for squidguard example: https://www.dalemacartney.com/2012/07/06/web-proxy-filtering-with-squidguard-using-active-directory-group-memberships/