As a word of advice, use AD LDAP over AD. The login performance is much better and you get a lot more options to auth against and use for permissions. We have a large install and login with AD was taking about 60 seconds. By changing this to AD LDAP, it's now ~<2 seconds Has to do with the way the boxes process group membership
... View more