LDAP and Active Directory are two different things.
Regular domain logon does not use LDAP interface at all. Actually, we don't see many applications use LDAP in a Microsoft environment.
CUPC uses LDAP interface for name resolution. If CUPC sent many queries in a short period and LDAP was not indexed, it might consume lots of CPU resource for those queries.
Since CUPC is the only application that using LDAP, it's quite easy to point fingers to it. But I would try to index LDAP. Or open a case with Microsoft to determine how many queries are "too many".
This happens to other Cisco applications that use LDAP (such as CUCIMOC).
Michael
http://htluo.blogspot.com