I don't believe you can make the rule on the user, it has to be on the AD group. Other than that, the rule will work. You need to have the domain registered within NSX and make sure you have the guest introspection VM installed on the cluster.
-Jake