At present AD integration is pretty much an all or nothing approach; you can define groups that are allowed to access VC, however, these are placed in the "Default" User role.
There is no way to, for example:
- Have one AD group that is for Administrator Role
- Have another AD group that is for Viewer / Read Only Role
etc