It may be not just only you that is missing something; I configured a client application to only have an Active Directory enterprise connection enabled and then did an
/authorize request in association with that client application.
The above took me to the centralized login (aka hosted login page (aka HLP)) where Lock was shown. I have a customized HLP, but only to change Lock primary color so this should be equivalent to the standard template (although I’m only using Lock 10.18 in mine). In this screen Lock did not even showed me the option to signup as it would be expected because to my knowledge there’s no way to signup a user into an AD connection; you can only authenticate against it.
You may want to update your question with additional details on your exact setup.