Generally speaking, yes. The process to provide management at a group and user level is to (1) Bind to the domain, (2) enroll into Profile Manager (requires enabling device enrollment in Server.app), (3) manage by setting policy to users (not very efficient), groups, devices, or device groups. Then, make sure you have added a push certificate to the server which will allow your policies to be pushed to the devices automatically. (You must allow push notification on your network) If you don't use push, you can press the Download button and distribute manually. But that does not scale well.
The idea here is that many of the services are designed to work independently but they enhance each other as you integrate them. For example, OD can be used without Profile Manager if you are looking to centralize your users, groups, and password policy. Profile Manager can be used without OD if you are looking to manage devices but not user accounts (BYOD, Apple ID centric deployments, etc). Likewise Profile Manager is really three services in one. It is the management of devices, VPP, and DEP. Each can be used in any combination depending on your needs.
Reid
Apple Consultants Network
Author "Yosemite Server – Foundation Services" :: Exclusively available in Apple's iBooks Store
Author "Mavericks Server – Foundation Services" :: Exclusively available in Apple's iBooks Store
Author "Mavericks Server – Control and Collaboration" :: Exclusively available in Apple's iBooks Store