Try to go into Users and Groups and add a user manually to the Administrators group just to check.
Also you are not specifying a primary server URL for connection and if you have any issue with the DNS maybe vCenter will not connect using ldap correcly so full fill at least the Primary Server URL like this: ldap://first_domain_controller:389 or ldaps://first_domain_controller:636
And regarding the query about the Domain Functional Level I believe is for Active Directory in general not only to Active Directory Integrated Authentication identity source because on the KB it does not discriminates on that type. However I am not 100% as it is not explicitly explained.