Radius is one valid option. Do you have ISE in your environment? What is the motivation to keep AD users separate from VPN user accounts? Anyways if using radius you will want to configure your VPN connection profile/s for AAA. If you desire to use certs & AAA this is an option too. In that scenario you would perform cert auth at the ASA and username/pass against your AAA server (radius), which could be local radius accounts or mapped to AD.