The docs around this topic aren't the greatest and I'm not the only one on this forum having this issue but the question still remains unanswered.
It's a little frustrating considering how expensive x-pack is and this functionality is almost elementary in other applications.
Unfortunately this isn't possible today with x-pack. We have a feature request to add an AD bind user to the product which will make this use case possible. Our LDAP authentication is able to use a bind user which will make this use case possible. The LDAP documentation can be found here:
https://www.elastic.co/guide/en/x-pack/current/ldap-realm.html
Thanks.