If you open enough ports, sure, which somewhat defeats the purpose of having the segments firewalled (note, that it is perfectly legitimate to use a pix like you are, with all the MS stuff open between the pix's interfaces, and just use the pix to block other stuff - management/monitoring apps, etc).
You will want tcp/udp 135 open, as well as tcp/udp 137-139, and tcp/udp 445 at a minimum. Win2k active directory will neep tcp/udp 88 for kerberos. If you are running wins, it uses 1512tcp and udp for replication between servers.
That is a start. That should work for NT 4, win2k AD might need some more ports opened, depending on topology