Hi Carl,
I know of 2 different ways to achieve this:
1) create 2 aaa-server groups, one for each domain; then create 2 tunnel-groups, each one pointing to a different aaa-server group.
This means of course that the users will have to select the correct tunnel-group (either from a drop-down list, or by going to the right group-url). For Anyconnect users, you can optionally deploy a different profile (i.e. with a different group name) to both sets of users.
2) assuming the 2 domains are in the same AD Forest, configure one (or more) DC to be a GCS (Global Catalog Server) for the Forest. Then on the ASA you can use the GCS as LDAP server to do multi-domain lookups.
Downside of this approach is that GCS cannot handle password changes.
hth
Herbert