You might want to set up a Web Active Directory solution in your DMZ and have it work with an Active Directory server behind the firewall on your internal network. You need to open up the appropriate ports to allow this communication from your DMZ to domain controllers behind the firewall on your internal network.
The following information helps you understand the Active Directory firewall ports you should open from your DMZ to your internal network to allow communication from a DMZ machine to an internal Active Directory domain controller. These ports relate to Active Directory and you should only need to open them if you do not have a Global Catalog (GC) or Domain Controller (DC) in your DMZ.
There might be some RPC ports that you need to open in addition and that question is probably best answered by your Microsoft technical account manager. The references also contain good information to help you gather more information.
You need to open at least the following two ports from your DMZ to your internal network to allow basic Active Directory communication
To enable replication over dynamic RPC, configure your firewall to permit the following (from Microsoft “Active Directory Replication over Firewalls” article in References section).