If you want specific ban lists per users, then you need to authenticate (Or at least assume) the user for WinGate to match up the policy to the connection / user.
As you're using Active Directory, your easiest authentication scheme would be NTLM. I assume you've switched WinGate to use the OS User Database. (Go to the User tab page, change database options). You've probably picked the AD Server as your synchronisation server too, correct?
Now go to the WWW Proxy Service and on the first page, make sure that the NTLM option is checked. Then, go to the policy and set it to "Must be authenticated". Your client browsers should now automatically authenticate using NTLM, for the user currently logged in on that Windows PC.
Have a look at our knowledge base as well,
http://support.qbik.com/index.php?_a=knowledgebase, for the articles regarding Active Directory and Authentication.