For best performance, you should run Microsoft Active Directory on a dedicated virtual machine. Tribal Knowledge says that it wouldn't hurt to keep the domain controller on a physical server to remove dependency on the hypervisor in case it fails.
By default, Director performs a forest-wide search of the logged in admin and Director machine's domain. As you start to scale up your XenDesktop site, Active Directory might slow you down, because, by default, all of the global catalogs for the Active Directory forest are searched with Lightweight Directory Access Protocol (LDAP). It is best to turn this off.
To disable AD Forest Searching, perform the following steps:
Log in as administrator.
Open IIS Manager.
Browse to
\Sites\Default Web Site\Director
in the left hand navigation frame.Select Application Settings.
Add a new value called ActiveDirectory.ForestSearch. Select Value as false.
Click Apply in Actions.
Run IISRESET to apply the changes.