I think we are getting mixed on our Terminology. The magic triangle is a term that came from the need to dual bind to both AD (the parent domain) and OD (the subordinate domain). The reasons for this back in the day was to provide management via MXC as the OD server provided a location to store MCX attributes without schema modification to AD. It was possible to manage OS X systems without the magic triangle by extending AD schema or by using tools like Centrify. But in most cases the prospect of schema extension was filled with dread and generally frowned upon by AD admins. And Centrify added significant cost to a deployment where OS X Server, even with the hardware, was a bargain.
Now MXC is dead. So the concept of the magic triangle may not make much sense or at the very least the term probably needs updating. However, there remains a need to store and manage settings. The settings are now configuration profiles and they are created on OS X Server (Profile Manager) or other MDM solutions. To make this work, the device must be enrolled into the MDM (Profile Manager, JAMF, Airwatch, etc) and your network must support Apple's push notification (or you an manually distribute for configuration profiles).
In your case you want to do the following:
• Keep users, groups, and passwords in AD
• Manage devices through Profile Manager (or another MDM)
Now, we get caught on semantics when talking about the magic triangle and binding. In reality, unless you need to create and use proxy groups in OD, there is no need to bind clients to an OD server. Instead, you would bind them to AD (for authentication and authorization) and then enroll the devices into your MDM to allow for device level management. Now with Profile Manager you can go right to enrollment if you have a binding profile created.
Start with a manual method. First, bind a machine to AD and make sure you can login. Next, get your server bound to AD and then promote to an OD Master so you can fire up Profile Manager. Enroll the workstation and then manage the device or create a device group and add the device to the group.
I hope that makes more sense. The concept of the magic triangle is a little dated due to its association to MCX.
Reid
Apple Consultants Network
Author "El Capitan Server – Foundation Services" :: Exclusively available in Apple's iBooks Store
Author "El Capitan Server – Control & Collaboration" :: Exclusively available in Apple's iBooks Store
Author of Yosemite Server and Mavericks Server books