Update the clients to OS X Lion v10.7.3 or later.
Learn more
Workaround for OS X Lion clients that are not ready to update to OS X Lion v10.7.3
To be able to bind to Active Directory when read-only domain controllers are present, first create the computer account in Active Directory. Next, verify that the computer account has successfully replicated to all read-only domain controllers by using the Active Directory Users and Computers management console.