Hello,
The procedure to join to a NAC domain is done automatically with the onboard SAMBA package that is deployed. In order to trigger this join attempt you must have an Advanced AAA configuration with at least one line set to "LDAP Authentication" and pointed to an LDAP configuration that is set to "NTLM Authentication"
The NAC determines who the domain controller is to attempt to join by doing a DNS lookup of the domain configured. 
The NAC uses the "user" and "Password" fields from the LDAP configuration to attempt to join the active directory. 
The NAC will attempt to re-join the active directory if a nacctl restart is issued, or if a configuration change is made that removes, and then reapplies the LDAP authentication or NTLM authentication configuration pieces.
Thanks
-Ryan