If you haven't already, you might consider the advantages (in an AD environment) of having your windows server doing DHCP as well. For example, if Windows is doing DHCP, the DHCP server can be configured to update the DNS server. At that point, if you have multiple vlans, you'd also want to enable the DHCP relay function on pfsense (or on a L3 switch.)