If you were to install a RADIUS server onto an AD domain controller and then somehow got SME to authenticate from that, then you would in effect be authenticating off the AD.
I do this all the time with RADIUS clients authenticating via a Cisco ACS server to an AD
However SME isn't designed (AFAIK) to allow remote authentication - you could add a NFR to the bug tracker to allow RADIUS auth.
Nick