No, basically the answer is Internet Explorer supports the use of pass through NTLM from the base operating system (XP/2000), no such method exists for LDAP (ADS) as it relies on the Kerberos tokens being issues and recognised by the the proxy device which the CE's currently don't support. You can do LDAP/ADS authentication if your using websense on box by relying on the Websense LDAP/ADS authentication which does work.
I did a fare amount of digging on this before I recieved confirmation that its not supported. The other potential gotcha is 2003 Server uses NTLMv2 by default if you plan on using that root. In the end my customer was happy to stick with the popup box as a potential security measure.
Mark