If you have any host that is on the domain, and you are only looking for hosts that are in your domain that are NT based, you can do this:
dsquery * "<YOUR BASE DN>" -scope subtree -filter "(operatingSystem=Windows NT*)"
if you are not on a machine which is part of the domain, if you have a valid user account inside the domain
ldapsearch -H ldap://
<any domain controller> -b "<your base ou>" -D "<fully qualified DN of a user in AD>" -W -x "(OperatingSystem=Windows NT*)"
You could run this on say a linux box against your ad structure, just having a user in the domain and this should get you what you want
If you are talking about walking into a network blind and finding out if there are NT boxes on the network, nmap is your friend
CISSP, CSSLP, MCSE+Security, MCTS, CCSP, GPEN, GWAPT, GCWN, NOP, OSCP, Security+