That would depend on a number of other elements.
For example, some environments have a dedicated VLAN for deploying new machines, and sometimes you can't even reach the AD domain from there.
I would place that in the OSCustomizationSpec in the RunOnce section, provided your VM already joined the domain at that point.