Hello Jim,
In order to implement this scenario you need a SAML Identity Provider. The SAML Identity Provider coming with SAP Single Sign-On product (license required) is the one that you have to deploy on AS Java Server in order to integrate your MS AD.
Regards,
Donka Dimitrova