There's nothing obvious to me unless you limited the attributes returned in the connector. I suggest you turn up the LDAP connector logging and see what it's returning. -- Scott