Hello Christoph,
In answer to your original post, you are correct  that NAC always strips off the Domain when doing an LDAP lookup on a  user.  Unfortunately, there is no current means by which to change this  behavior.  This could be put forward as a Feature Request for possible  future functionality; however, I do not have an immediate means by which  to work-around this behavior in an LDAP configuration.   
If you do wish  to raise this as a Feature Request, this can be started with opening a  Services Case by either calling into the GTAC, or via the Case  Management Web Portal.  If you would submit the request in the Services  Case, we can then take it over to a formal Feature Request for possible  future functionality, and will relay it to the appropriate Product  Manager for review. 
Best Regards,
Gregory K. Hayden
Technical Support Specialist
Enterasys, now part of Extreme Networks
+1 603-952-6781