It most definitely needs to be done via ADSI, either using the ADSI extender, or using the ADSI COM interfaces. The NT extender simply does not have access to that information via the Win32 API functions that access AD through the legacy SAM database interfaces.