I don't quite see why you conclude that it's the shortname "brendan" that's being used when searching for group memberships, but if that's correct, maybe you can work around it by changing the groupmembership_filter to: groupmembership_filter = "(&(objectClass=GroupOfNames)(member=uid=%{User-Name},ou=Users,dc=bpk2,dc=com))" -jf