Correct install the Synology Directory Server package from the package center and set up your Windows Domain. It's an excellent choice for small businesses.
After successfully adding your NAS to your AD domain, you can then configure access rights using the Domain Users, Domain Groups and Shared Folders settings ...
You certainly can. I have one client where their Synology is their everything. It is their domain controller, DNS server, Directory server and File server.