If you want to do that then you really need to have the AD server on a separate DMZ. Even private vlans would not help in this situation because the AD server needs to communicate with other LAN servers.
So you would need a DMZ on the firewall for the AD server or at the very least a different vlan for the AD server that you can apply an access-list to.
Having said that if you did move your AD server to a DMZ then you would have to open a fair few ports to allow it to communicate to the servers on the LAN.
It's not an easy thing to do either way.
Jon