For the record, it looks like the hangs that I was seeing have been fixed in the newly released 10.2.2:

# Addresses a startup issue that could occur if an LDAP server designated in Directory Access is not available.

It's possible that when I configured AD support, one of the servers I added went down.

As far as the overall AD implemetation, there is no easy way for me to get it working without some changes server side. I can change a few fields on my own user account in the directory, thus I could add all I need, but it would serve no benefit, as noone else would be able to authenticate and login without similar changes to their account. And AD out of the box is very Windows centric. Adding Services for Unix to the top level domain controller would add the needed schema changes (ie UID, Unix stored home directory, etc...), but that is not implemented on my work network.