Yes, you can implement a RADIUS AAA server solution like the Cisco ACS server. With this you can prompt for user authentication after PHASE I of the VPN connection. The user will be prompted for a username and password which the PIX will then forward to the ACS which will be pointed to the Active Directory database for users authentication.
You could also configure the VPN client to create the VPN tunnel before login so that when the users log into the network (after the VPN connection) they will loggin directly into the Domain and their login scripts will run etc...
Hope this helps,
Curt