Trying to get limitations in policies working with Active Directory. We
have LDAP connectors and they can resolve users and groups, but cannot
list members IN groups. It does work if the user is directly listed in
the AD group, but not if they exist ...