Check the Forgerock document that shows a step-by-step recipe on how to properly configure OpenAM to use Microsoft Active Directory for both Authentication and (if desired) as a DataStore (sometimes referred to as the IDRepo or the User Profile store). Note this procedure is for post installation.
Configure OpenAM to use Active Directory for Authentication and DataStore