When you change into the vfiler shell (with the vfiler context command) are you able to ping the Domain Controller in the AD?
If yes, and you have a CIFS licence, run "cifs setup" in the vfiler shell to join the vfiler into the AD.
You can connect with the Windows Computer Management MMC to the vfiler and create shares and modify sharelevel ACLs.
If the volumes/qtrees have NTFS security style, you can laso connect to the shares and administer the file/directory ACLs.
Otherwise, check documentation on NOW.netapp.com.